Cloud environment-oriented data stealing evidence chain generation method and system
By building a data-stealing evidence link in a cloud environment, using in-depth analysis and risk assessment models, the problem of detection and evidence collection between virtual machines is solved, and efficient traceability of malicious theft behavior and tampering detection of evidence links is achieved.
Patent Information
- Application Number
- CN202510751845.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the cloud computing environment, the existing technology lacks in-depth analysis of the east-west traffic of virtual machines, and cannot effectively deal with file-free attacks and zero-day vulnerability exploits. Moreover, multi-dimensional evidence is difficult to correlate when collecting evidence, and logs are easily tampered with or deleted.
The data-stealing evidence link generation method for cloud environments is adopted, and the virtual machine file transfer operation records are collected, behavior feature sets are constructed, and the long-term memory network and Transformer model are used to evaluate the risk of malicious theft, and the Merck tree-type malicious evidence link is constructed, and the SHA256 hash algorithm is combined to ensure the integrity of the evidence link.
Accurately extract the hidden stealing mode in the high-dimensional, sparse and noise-prone cloud transmission log, complete tamper verification in a short time, trace the attacker's behavior, distinguish scripted batch theft from manual targeted penetration, and provide interactive evidence maps to support detailed analysis.
Smart Images

Figure CN120281576A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method and system for generating an evidence chain of data theft for a cloud environment, belonging to the technical fields of cloud computing security and digital forensics. Background Art
[0002] In a cloud computing environment, data security faces severe challenges, especially the detection and forensics of lateral movement attacks (such as ransomware and APT attacks) between virtual machines. Existing technologies have significant defects: lack of in-depth analysis of the east-west traffic of virtual machines; detection methods based on virus signatures or known malicious hashes cannot effectively cope with new threats such as fileless attacks and zero-day vulnerability exploitations; data such as network traffic, file operations, and process behaviors are stored dispersedly, making it difficult to correlate multi-dimensional evidence during forensics, and logs are easily tampered with or deleted. Summary of the Invention
[0003] In order to solve the problems existing in the above-mentioned prior art, the present invention proposes a method and system for generating an evidence chain of data theft for a cloud environment.
[0004] The technical solution of the present invention is as follows: On the one hand, the present invention provides a method for generating an evidence chain of data theft for a cloud environment, including the following steps: Collect the file transfer operation records of cloud virtual machines, and at the same time preset rules to judge whether the file corresponding to each file transfer operation record is a sensitive file; Extract all the behavior characteristics during the transmission of the sensitive file based on the file transfer operation records of the sensitive file, and construct them into a behavior characteristic set; Construct a dynamic risk assessment model, and evaluate the malicious theft risk score of the current sensitive file transfer operation record based on the behavior characteristic set of the sensitive file through the dynamic risk assessment model; If the malicious theft risk score is greater than the preset malicious theft risk score threshold, extract the operation characteristics in the file transfer operation record in chronological order to construct an operation characteristic time series, and construct a malicious theft evidence chain based on the operation characteristic time series.
[0005] Preferably, the dynamic risk assessment model is constructed based on a long short-term memory network model and a Transformer model.
[0006] Preferably, the calculation formula for the malicious theft risk score is: ; Where: represents the malicious theft risk score; represents the total number of behavior characteristics in the behavior characteristic set; represents the The basic threat score of a behavior feature; Indicates the dynamic weight of the behavior feature; Indicates the timing penalty factor; Indicates the set of behavior features; Indicates the timing features of the set of behavior features extracted by the long short-term memory network model.
[0007] Preferably, the dynamic weight of the behavior feature is calculated based on the Transformer model; The input of the Transformer model is the set of behavior features and the statistical data corresponding to historical risk events; The Transformer model outputs the dynamic weight of each behavior feature in the current set of behavior features.
[0008] Preferably, the calculation formula for the malicious theft risk score threshold is: ; Where: Indicates the malicious theft risk score threshold; Indicates the average value of historical malicious theft risk scores; Indicates the standard deviation of historical malicious theft risk scores.
[0009] Preferably, the malicious theft evidence chain is in the form of a Merkle tree structure.
[0010] Preferably, the steps for constructing the malicious theft evidence chain are as follows: For each operation in the operation feature time series, combine the sensitive file transfer target IP, the sensitive file hash check value, the current operation feature, and its corresponding execution time, calculate the hash value through the SHA256 hash algorithm, and construct it as a leaf node; Sort all leaf nodes in the order of the execution time of the behavior features. For every two adjacent leaf nodes, calculate the execution time difference between them. Combine the execution time difference and the hash values of the two leaf nodes, calculate the hash value through the SHA256 hash algorithm, and construct it as a parent node; Repeat the above steps until a root node is obtained, and use the hash value of the root node as the only credential of the malicious theft evidence chain.
[0011] On the other hand, the present invention also provides a data theft evidence chain generation system for cloud environments, including a data collection module, a behavior feature extraction module, a malicious theft risk assessment module, and a malicious theft evidence chain construction module; The data collection module is used to collect the file transfer operation records of cloud virtual machines, and at the same time, preset rules to judge whether the file corresponding to each file transfer operation record is a sensitive file; The described behavior feature extraction module is used to extract all behavior features during the transmission process of a sensitive file based on the file transfer operation record of the sensitive file, and construct them into a behavior feature set; The described malicious theft risk assessment module is used to construct a dynamic risk assessment model, and evaluate the malicious theft risk score of the current sensitive file transfer operation record based on the behavior feature set of the sensitive file through the dynamic risk assessment model; The described malicious theft evidence chain construction module is used to extract operation features in the file transfer operation record in chronological order to construct an operation feature time series, and construct a malicious theft evidence chain based on the operation feature time series.
[0012] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in the present invention is implemented.
[0013] On the other hand, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the method described in the present invention is implemented.
[0014] The present invention has the following beneficial effects: 1. By dynamically fusing the near-neighbor time series dependence extracted by LSTM and the long-distance global association captured by Transformer, the present solution can accurately refine hidden theft patterns in high-dimensional, sparse, and significantly noisy cloud transmission logs.
[0015] 2. Taking the sensitive file hash + target IP + behavior feature + execution time as the minimum leaf node, recursively calculating the parent node until the root hash can complete the tampering verification in a short time; explicitly writing the execution time difference between adjacent operations between leaf nodes, and then calculating the parent hash, so that the chain retains both the operation order and rhythm information; subsequent traceability can intuitively restore the accurate rhythm of the attacker, which helps to distinguish scripted batch theft from manual targeted penetration. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a flowchart of the method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0018] It should be understood that the step numbers used in the text are only for convenience of description and do not limit the order of execution of the steps.
[0019] It should be understood that the terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms.
[0020] The terms "comprising" and "including" indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations.
[0021] The term "and / or" refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0022] Embodiment 1: See Figure 1 , a method for generating an evidence chain of data theft for a cloud environment, comprising the following steps: Collect the file transfer operation records of the cloud virtual machine (file transfer target IP location, transfer period, file operation sequence, whether process injection, whether memory tampering, etc.), and at the same time preset rules to judge whether the file corresponding to each file transfer operation record is a sensitive file; Extract all the behavioral characteristics during the transfer of the sensitive file based on the file transfer operation record of the sensitive file, and construct them into a behavioral characteristic set; Construct a dynamic risk assessment model, and evaluate the malicious theft risk score of the current sensitive file transfer operation record based on the behavioral characteristic set of the sensitive file through the dynamic risk assessment model; If the malicious theft risk score is greater than the preset malicious theft risk score threshold, extract the operation characteristics in the file transfer operation record in chronological order to construct an operation characteristic time series, and construct a malicious theft evidence chain based on the operation characteristic time series.
[0023] In this embodiment, by deploying a lightweight probe at the Hypervisor layer of the cloud virtual machine, the east-west traffic of the virtual machine is captured through the BPF technology, and the east-west traffic includes source IP, destination IP, source port, destination port, protocol type, timestamp, and file check hash value, etc.; The east-west traffic parsing of data is performed based on the lightweight probe-based cache-utilized Deep Packet Inspection (DPI) technology and the multi-protocol parsing engine. The transmitted file is restored based on the cache and the file transfer operation records are reconstructed. For example, at 03:15:20, the financial file salary.xlsx was encrypted, at 03:15:22, the encrypted file was transferred to 54.239.25.200, and at 03:15:25, the encrypted file was deleted after the transfer was completed; Behavioral features are extracted based on the above file transfer operation records, and the basic threat scores of each behavioral feature are set as shown in the following table:
[0024] After constructing the above behavioral features into a behavioral feature set, it is input into the dynamic risk assessment model, and the dynamic risk assessment model is constructed based on the long short-term memory network model and the Transformer model; The malicious theft risk score is calculated based on the dynamic risk assessment model, as shown in the following formula: ; Where: represents the malicious theft risk score; represents the total number of behavioral features in the behavioral feature set; represents the basic threat score of the th behavioral feature; represents the dynamic weight of the th behavioral feature; represents the time series penalty factor; represents the behavioral feature set; represents the time series features of the behavioral feature set extracted by the long short-term memory network model; The dynamic weight of the behavioral feature is calculated based on the Transformer model; The frequency of attacks on this risk IP (54.239.25.200) has increased by 35% recently. Based on this feature, the dynamic weight coefficient of the behavioral feature "target IP is a high risk" calculated by the Transformer model is 2.1; The abnormal login frequency has increased by 50% recently. Based on this feature, the dynamic weight coefficient of the behavioral feature "transmission during non-working hours" calculated by the Transformer model is 1.6.
[0025] The dynamic weight coefficient of the "immediate transmission after file encryption" behavioral feature calculated by the Transformer model based on the time interval is 2.3; The time series features of the behavioral feature set are extracted by the long short-term memory network model and multiplied by the time series penalty factor to obtain a penalty value of 28; Based on the above data, the malicious theft risk score is calculated as 310 through the above formula; As a preferred implementation of this embodiment, the formula for calculating the malicious theft risk score threshold is: ; Where: represents the malicious theft risk score threshold; represents the average value of historical malicious theft risk scores; represents the standard deviation of historical malicious theft risk scores; In this embodiment, the malicious theft risk score threshold is calculated based on the malicious theft risk scores of the past 7 days. The malicious theft risk scores of the past 7 days are , then the malicious theft risk score threshold calculated through the above formula is ; The current malicious theft risk score , triggering the construction of the malicious theft evidence chain; As a preferred implementation of this embodiment, the malicious theft evidence chain is a Merkle tree structure. The steps for constructing the malicious theft evidence chain are as follows: Extract the operation features in the file transfer operation record in chronological order to construct an operation feature time series as ; For each operation in the operation feature time series, combine the sensitive file transfer target IP, sensitive file hash check value, current operation feature, and its corresponding execution time, calculate the hash value through the SHA256 hash algorithm, and construct it into a leaf node, as shown in the following formula: ; Where: represents the leaf node; represents the SHA256 hash algorithm; represents the current operation feature; represents the operation-related file; represents the sensitive file transfer target IP; represents or; represents the sensitive file hash check value; represents the operation execution time; represents the concatenation operation; Sort all leaf nodes in chronological order according to their behavioral characteristics. For every two adjacent leaf nodes, calculate the time difference of operation execution. Combine the time difference of operation execution and the hash values of the two leaf nodes, and then calculate the hash value through the SHA256 hash algorithm to construct a parent node, as shown in the following formula: ; Where: represents the parent node; represents the left child leaf of the parent node; represents the right child leaf of the parent node; represents the time difference of operation execution between the left child leaf and the right child leaf; In this embodiment, two parent nodes can be constructed from the leaf nodes, as shown in the following formula: ; ; Where: represents the first parent node; represents the leaf node constructed by ; represents the leaf node constructed by ; represents the time difference of operation execution between the left child leaf and the right child leaf of the parent node; represents the second parent node; represents the leaf node constructed by ; Repeat the above steps until a root node is obtained. Take the hash value of the root node as the only credential of the malicious theft evidence chain. In this implementation, the root node is represented as ; In this embodiment, write the root node into the cloud platform audit log and append the timestamps of the head and tail leaf nodes to restore the complete event line; When a new operation feature arrives, create a new leaf node; Starting from the new leaf node, update the hash value of the Merkle tree upward until the root node; Use the version control mechanism to record the timestamp and version information of each update to ensure the traceability of the update process.
[0026] The Merkle tree is also equipped with an anti-tampering mechanism. For example, when an attacker attempts to modify the transmission time in to (earlier than the encryption time), at this time the parent node will change, resulting in a change in the root node. When a time sequence contradiction is detected, restore it to the original value and give feedback on the risk at the same time.
[0027] In this embodiment, an interactive evidence graph is constructed based on the malicious theft evidence chain. The interactive evidence graph includes a three-dimensional linkage view of a timeline, a process tree, and a network topology, and supports drilling down to view the original evidence data under nodes.
[0028] Timeline view: Displays the attack event sequence with millisecond precision; supports filtering by time range; Process tree view: Highlights malicious processes and their injection paths in red; displays key API calls in process memory (obtained through VMI technology); Network topology view: Overlays VPC flow log data and renders abnormal traffic paths.
[0029] The steps for implementing the interactive evidence graph are as follows: 1. Locate abnormal nodes: Verify layer by layer from the root node. If the root hash does not match the record in the cloud platform, it indicates that the evidence chain has been tampered with; by checking the hashes of the parent nodes and leaf nodes layer by layer and , the tampering location can be located; 2. Extract event metadata: Each leaf node stores complete event information, including: operation type, associated file / IP, file hash, timestamp.
[0030] 3. Combine data association analysis: Combine traffic and system log association analysis.
[0031] Embodiment 2: Anti-tampering verification of the evidence chain for financial data theft attacks: 1. Restore the attack scenario (1) Process injection (03:15:20): The attacker injects malicious code into the legitimate process explorer.exe through a vulnerability.
[0032] (2) File encryption (03:15:22.423): The injected process calls cipher.exe to encrypt the financial file salary.xlsx.
[0033] (3) External data transfer (03:15:25.800): Transmits the encrypted file to the overseas IP 45.67.89.123 via HTTPS.
[0034] (4) File deletion (03:15:26.200): Deletes the local encrypted file copy.
[0035] 2. Construct a Merkle tree Leaf node hash calculation data field format: <operation type>_<target>_<file / IP>_<timestamp> ; ; ; ; Wherein: represents empty; 、 、 、 respectively represent the hash values corresponding to the leaf nodes; Parent node hash calculation: # represents the time-consuming from process injection to file encryption; ; # represents the time-consuming from external data transfer to file deletion; ; Wherein: 、 respectively represent the hash values of the parent node; Root node Calculation (total time span 6.2 seconds) # represents the total time-consuming from process injection to file deletion; ; Write the root node hash value into the cloud platform storage; 3. The attacker attempts to tamper with (1) Forge the target IP of Leaf3 as the internal network IP 192.168.1.100, attempting to cover up the trace of external data transfer: ; At this time, the hash value of this leaf node is ; Recalculate the hash of the parent node Parent2: ; At this time, the hash value of the parent node Parent2 is ; The hash of the root node also changes: ; At this time, the hash value of the root node ; The root hash stored in the cloud platform ( ) does not match the tampered hash ( ), and the tampering behavior is detected.
[0036] Example Three: A data theft evidence chain generation system for cloud environment, including a data collection module, a behavior feature extraction module, a malicious theft risk assessment module, and a malicious theft evidence chain construction module; The data collection module is used to collect the file transfer operation records of cloud virtual machines, and preset rules to judge whether the file corresponding to each file transfer operation record is a sensitive file; The behavior feature extraction module is used to extract all behavior features during the transmission of the sensitive file based on the file transfer operation records of the sensitive file, and construct them into a behavior feature set; The malicious theft risk assessment module is used to construct a dynamic risk assessment model, and evaluate the malicious theft risk score of the current sensitive file transfer operation record based on the behavior feature set of the sensitive file through the dynamic risk assessment model; The malicious theft evidence chain construction module is used to extract the operation features in the file transfer operation records in chronological order to construct an operation feature time series, and construct a malicious theft evidence chain based on the operation feature time series.
[0037] This system is used to implement the method in Embodiment 1, which will not be elaborated here.
[0038] Embodiment 4: This embodiment provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method described in any embodiment of the present invention.
[0039] Embodiment 5: This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method described in any embodiment of the present invention.
[0040] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent the situation of A existing alone, A and B existing simultaneously, and B existing alone. Where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" and its similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0041] Those of ordinary skill in the art will realize that the various units and algorithm steps described in the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0042] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0043] In several embodiments provided by this application, if any function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.
[0044] The above are only the embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent structural or equivalent process transformation made using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A method for generating an evidence chain of data theft in a cloud environment, characterized in that It includes the following steps: Collect the file transfer operation records of the cloud virtual machine, and at the same time, use preset rules to judge whether the file corresponding to each file transfer operation record is a sensitive file; Extract all the behavioral characteristics during the transfer of the sensitive file based on the file transfer operation records of the sensitive file, and construct them into a behavioral characteristic set; Construct a dynamic risk assessment model, and use the dynamic risk assessment model to evaluate the malicious theft risk score of the current sensitive file transfer operation record based on the behavioral characteristic set of the sensitive file; If the malicious theft risk score is greater than the preset malicious theft risk score threshold, extract the operation characteristics in the file transfer operation record in chronological order to construct an operation characteristic time series, and construct a malicious theft evidence chain based on the operation characteristic time series.
2. The method for generating an evidence chain of data theft faced to a cloud environment according to claim 1, wherein The dynamic risk assessment model is constructed based on the long short-term memory network model and the Transformer model.
3. A method for generating an evidence chain of data theft in a cloud environment according to claim 2, wherein The calculation formula of the malicious theft risk score is: ; Wherein: represents the malicious theft risk score; represents the total number of behavior characteristics in the behavior characteristic set; represents the basic threat score of the th behavior characteristic; represents the time series penalty factor; represents the behavior characteristic set; represents the time series characteristics of the behavior characteristic set extracted by the long short-term memory network model.
4. A method for generating an evidence chain of data theft in a cloud environment according to claim 3, characterized in that, The dynamic weight of the behavioral characteristics is calculated based on the Transformer model; The input of the Transformer model is the behavioral characteristic set and the statistical data corresponding to historical risk events; The Transformer model outputs the dynamic weight of each behavioral characteristic in the current behavioral characteristic set.
5. A method for generating an evidence chain of data theft in a cloud environment according to claim 1, wherein The calculation formula of the malicious theft risk score threshold is: ; Wherein: represents the malicious theft risk score threshold; represents the average historical malicious theft risk score; represents the standard deviation of the historical malicious theft risk score.
6. The method for generating an evidence chain of data theft in a cloud environment according to claim 1, wherein The malicious theft evidence chain is a Merkle tree structure.
7. A method for generating an evidence chain of data theft for a cloud environment according to claim 6, characterized in that The construction steps of the malicious theft evidence chain are: For each operation in the operation characteristic time series, combine the sensitive file transfer target IP, the sensitive file hash check value, the current operation characteristic and its corresponding execution time, calculate the hash value through the SHA256 hash algorithm, and construct it into a leaf node; Sort all the leaf nodes in the order of the execution time of the behavioral characteristics. For every two adjacent leaf nodes, calculate the execution time difference between them, combine the execution time difference and the hash values of the two leaf nodes, calculate the hash value through the SHA256 hash algorithm, and construct it into a parent node; Repeat the above steps until a root node is obtained, and use the hash value of the root node as the only voucher for the malicious theft evidence chain.
8. A data theft evidence chain generation system for cloud environment, characterized in that, It includes a data collection module, a behavioral characteristic extraction module, a malicious theft risk assessment module, and a malicious theft evidence chain construction module; The data collection module is used to collect the file transfer operation records of the cloud virtual machine, and at the same time, use preset rules to judge whether the file corresponding to each file transfer operation record is a sensitive file; The behavioral characteristic extraction module is used to extract all the behavioral characteristics during the transfer of the sensitive file based on the file transfer operation records of the sensitive file, and construct them into a behavioral characteristic set; The malicious theft risk assessment module is used to construct a dynamic risk assessment model, and use the dynamic risk assessment model to evaluate the malicious theft risk score of the current sensitive file transfer operation record based on the behavioral characteristic set of the sensitive file; The malicious theft evidence chain construction module is used to extract the operation characteristics in the file transfer operation record in chronological order to construct an operation characteristic time series, and construct a malicious theft evidence chain based on the operation characteristic time series.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Malicious class detection method and related device
CN116861427A
Cloud virtual machine memory malicious behavior tracing and evidence obtaining method
CN117519893A
File data security management method and system based on artificial intelligence
CN120068111A
Cited By
Industrial data secure storage and verification method and system in trusted computing environment
CN120744960A
Methods and systems for secure storage and verification of industrial data in a trusted computing environment
CN120744960B
Intrusion detection system based on big data analysis
CN120811756A