Power grid attack resource automatic arrangement method

Through an automated orchestration method based on attack diagrams and attack models, the problem of difficulty in adapting attack resources in the power system network is solved, and the automatic orchestration and packaging of attack resources is realized, improving the efficiency and accuracy of network security defense.

CN120281667APending Publication Date: 2025-07-08南京聚沙电力科技有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510452188.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively build an attack map and attack model that meets the network application scenarios of power system, which leads to difficulty in adapting attack resources and is unable to realize attacker's attack strategy perception and prediction.

Method used

The attack resource adaptation method and attack resource automatic orchestration method are adopted based on attack graphs. Through the attack execution process description language and attack resource automation orchestration engine, combined with attribute attack graphs and attack models, the automatic orchestration and encapsulation of attack resources is achieved.

Benefits of technology

It realizes the automated orchestration and packaging of network attack resources in the power system, improves the adaptability of attack resources and attack types, assists security personnel in optimizing configuration, and improves the efficiency and accuracy of network security defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281667A_ABST
    Figure CN120281667A_ABST
Patent Text Reader

Abstract

The invention discloses a power grid attack resource automatic arrangement method, which relates to the technical field of network security defense, and adopts an OWL ontology description language to carry out formalized description and representation on a target system security state and attack resource information. Unified knowledge representation of a target system, security vulnerabilities, an attack process and attack resource information in the power system network is realized; completely modeling to implement attack resource sets on which different types of atomic attacks depend, and analyzing an attack model to obtain the attack resource sets required by different stages and different nodes in the attack process, so as to realize the adaptation of attack resources and attack types; under the guidance of an attack strategy, an execution path description language is introduced to describe an arrangement and packaging mode of attack resources required in an attack execution process, and an automatic arrangement engine of the attack resources is developed to automatically realize arrangement and packaging of the network attack resources of the power system. And thus, the purpose of automatically executing penetration utilization and attack on the target system by using the packaged attack resources is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security defense, and specifically to an automatic orchestration method for power grid attack resources. Background Technique

[0002] An intelligent honeynet is an active defense mechanism. To verify the trapping ability of the intelligent honeynet, an attacker is required as an opponent. Therefore, the automatic orchestration technology of power grid attack resources is an indispensable part of the key technology verification link of the intelligent honeynet. The active defense system based on the distributed intelligent honeynet can not only improve the security protection ability of the power system network, but also realize the traceability of attacks and the acquisition of attacker information through the active trapping of honeypots, thereby protecting the power system network from malicious attacks. The identification, early warning, and simulation of attacks are the premise and foundation for realizing the distributed intelligent honeynet of the power system network.

[0003] There are a wide variety of devices and services in the power system network, which means that there are various attack methods and means for the power system network. The attack modeling for different types of devices and services needs to meet the real application scenarios of the power system network, and its complexity poses challenges to the adaptation of attack resources. How to construct an attack graph and attack model that conform to the application scenarios of the power system network, and then realize the automatic adaptation of attack resources.

[0004] The Chinese patent "CN115442133A A Defense Automation Process Orchestration Method Based on SOAR" discloses a defense automation process orchestration method based on SOAR, including: automated analysis, research, and evidence collection of network attack behaviors based on the open-set transfer learning algorithm; automated orchestration technology for network attack responses based on SOAR; defense automation process orchestration scripts based on SOAR. The present invention deeply studies the automated response processes for events of different threat levels in various security scenarios, designs defense automation process orchestration scripts based on SOAR, and performs automated response handling for security device alarms of different risk levels, solving the problem of difficult timely discovery and automated response handling of high-risk and high-threat security device alarm events in a large number of alarms, achieving the purpose of improving the efficiency of network attack behavior responses, effectively reducing the threats brought by network attacks, assisting the power grid in improving the network security protection system, and significantly reducing the labor costs of network security operations. This patent uses automated means to replace manual handling, greatly reducing the response time of network security incidents and significantly improving the response efficiency. At the same time, this technology also realizes the full-range automated extraction and analysis of relevant information of the attacker, improving the efficiency of effective information filtering and reducing labor costs. Through cooperation with network security protection devices at the edge, it realizes the automated orchestration of network attack behavior defense work in the new power system, making its screening more accurate, response more convenient, and handling more efficient, building a solid fortress for network security protection in the new power system, reducing the probability of security risks caused by poor network attack behavior response efficiency, effectively helping the power grid improve the network security management system, further improving the response efficiency of network security incidents, and achieving further strengthening of network security protection management measures.

[0005] The Chinese patent "CN116318818A Network Security Intelligent Decision Automatic Orchestration Response Method and System" discloses a network security intelligent decision automatic orchestration response method and system, which constructs a vulnerability attack and defense knowledge graph based on network vulnerability attack information; performs alarm detection on network attack behaviors, and maps the environmental status of the alarm detection results to the status nodes of the vulnerability attack and defense knowledge graph through matching and mapping, where the environmental status includes: network environment and attack information; responds to the alarm information based on the known vulnerability attack and defense knowledge graph status nodes, response security decision set and attack type, and configures the firewall according to the response decision. The present invention integrates the construction of a vulnerability attack and defense knowledge graph, network attack alarm and policy script orchestration to meet the needs of security operation and maintenance services, can achieve timely and efficient response when facing attacks, and is convenient for network deployment. Through the coordinated cooperation of the vulnerability attack and defense knowledge graph, intrusion detection and automatic response intelligent decision based on reinforcement learning, the present invention realizes the visual description of the network environment status, the accurate detection of network abnormal traffic, the orchestration of emergency response strategies and targeted defense actions. This technical solution has good migration ability, can be applied to network implementation alarm response and decision defense in various environments, and has broad application prospects. At the same time, the present invention also uses deep learning technology to introduce a neural network, optimize the state-action value function, map the attack mode to the response security decision, and adaptively optimize the response security decision through online learning, improving the level of network security intelligence.

[0006] Chinese Patent "CN114070629A Security Orchestration and Automation Response Method, Device and System for APT Attacks". A security orchestration and automation response method, device and system for APT attacks. The method includes obtaining log data; obtaining a local threat intelligence library, which includes threat subject information, access mode information, attack target information and attack metric information for threat judgment and analysis; based on an artificial intelligence method, performing rule matching on the log data to generate security threat event alerts; using the local threat intelligence library to analyze the security threat event alerts to identify alert data; classifying the severity of the identified alert data, and according to the preset association relationship between the alert severity and the response playbook, performing response operations on the attack source and issuing a warning. The present invention can achieve high speed and efficiency of security response, short average fault response time, and greatly improve the effectiveness and maturity of security operations. This patent is a security orchestration and automation response method, device and system for APT attacks. The method includes obtaining log data; obtaining a local threat intelligence library, which includes threat subject information, access mode information, attack target information and attack metric information for threat judgment and analysis; based on an artificial intelligence method, performing rule matching on the log data to generate security threat event alerts; using the local threat intelligence library to analyze the security threat event alerts to identify alert data; classifying the severity of the identified alert data, and according to the preset association relationship between the alert severity and the response playbook, performing response operations on the attack source and issuing a warning. The present invention can achieve high speed and efficiency of security response, short average fault response time, and greatly improve the effectiveness and maturity of security operations.

[0007] Compared with the prior art, the prominent technical solution of the present invention aims at the problems of difficult perception of attack strategies and reconstruction of attack scenarios, and adopts an attack resource adaptation method and an attack resource automatic orchestration method based on an attack graph to solve the problems of attack strategy perception and prediction of attackers. Facing the requirements of power system network attack scenario simulation and attack process prediction, based on the monotonicity assumption, fully utilize the characteristics of the target system, vulnerability information, and attack resource information to construct an attribute attack graph to completely express the set of attack paths for attacking the target system; adopt an attack model construction and attack resource adaptation method based on the attribute attack graph to completely model the set of attack resources required for implementing different types of atomic attacks, and obtain the set of attack resources required at different stages and different nodes during the attack process through the analysis of the attack model, so as to realize the adaptation of attack resources and attack types. Summary of the Invention

[0008] Aiming at the deficiencies of the prior art, the present invention provides a method for automatically orchestrating power grid attack resources, which solves the problems put forward in the above background technology.

[0009] To achieve the above objectives, the present invention is implemented through the following technical solutions: An automatic orchestration method for power grid attack resources is as follows:

[0010] S1. The attack execution process description language describes the attack paths implemented during the attack in an accurate and concise manner, as well as the relationship between the node attack states and attack resources in the attack paths. Since the attack graph describes the effective attack paths for attacking the target system, and the adaptation method of the attack model and attack resources determines the set of attack resources for implementing a specific attack, an execution process description language is adopted to accurately depict the attack process, attack states, attack resources and their mutual relationships for attacking the target system; among which, extensible markup language is used to implement the operation;

[0011] S2. An attack resource automatic orchestration engine based on the attack execution process description language studies the attack resource automatic orchestration engine to achieve the orchestration and encapsulation of the attack resources required during the attack execution described by the execution path description language under the guidance of the attack strategy, and automatically executes the penetration exploitation and attack on the target system using the encapsulated attack resources; since the attack execution process description language is represented by an interpretive language, and the interpretive language has the ability to describe processes, the attack resource automatic orchestration engine realizes the automatic orchestration of attack resources according to the attribute attack graph and its attack execution process representation;

[0012] S3. Visualization of the attack execution process orchestration. The visualization method of the attack execution process and attack resource orchestration helps to realize the visual configuration and editing of the attack objectives, strategies, paths, methods and attack resource sets, and assist security personnel in optimizing the configuration; among which, Graphviz is used to implement the operation, and Graphviz is used to draw the graph described by the DOT language script; Graphviz consists of a graph description language called the DOT language and a set of tools for generating and / or processing DOT files; therefore, in order to realize the visual orchestration of the attack execution process, Graphviz is used to realize the visual orchestration of the attack execution process in the attack graph;

[0013] Among them,

[0014] For the power system network, a unified representation of attack objectives and resources based on ontology is constructed. On the basis of comprehensively analyzing the power system network devices and systems, vulnerabilities, attacks and attack resources, a method for constructing a network attack ontology model integrating the ATT&CK attack model for the power system network is proposed. By jointly modeling the target system, vulnerabilities, attack models and attack resources, the association and integration of discrete system and vulnerability information and corresponding attack means are realized, and then a network attack knowledge graph is constructed to realize the unified representation of power system network attack objectives and attack resources based on ontology.

[0015] Optionally, the Extensible Markup Language is used in S1 to mark electronic files to make them structured; the XML language allows users to perform data marking, data type definition, and allows users to create their own markup languages, and provides a unified way to describe structured data; since XML files can clearly describe the mutual relationships and related attribute information among the attack process, attack status, and attack resources during an attack, and at the same time, its parsing function is also convenient for guiding the attack on the target system by combining attack resources based on the attribute attack graph, therefore, a class XML language is used as the attack execution process description language to describe and parse the attack graph and attack resources.

[0016] Optionally, the technical set of the ATT&CK attack model uses the agglomerative hierarchical clustering algorithm, and a statistical hypothesis testing step is added to the clustering process. With the help of the statistical hypothesis testing results, the validity of the clustering results is verified, and at the same time, the optimal number of clusters is determined. The null hypothesis verification used in the statistical hypothesis testing step uses a part of the data analysis experiment, which means that a hypothesis is established in advance when conducting a statistical test. When the null hypothesis holds, the relevant statistic should follow a known probability distribution, and when the calculated value of the statistic falls into the rejection region;

[0017] The statistical hypothesis testing is combined with the clustering algorithm. The tree structure generated by the ATT&CK dataset is compared with the tree generated by the null distribution to analyze the effectiveness of the clustering, and it is allowed to infer statistically significant results at the required confidence level. The dataset used for the statistical hypothesis testing is generated by a random Bernoulli distribution, and the generated data has the same variance as the ATT&CK dataset. The empty tree generated on the random dataset is denoted as T0; if the number of clusters in the specified stage height TD is significantly different from the number of clusters in T0, then the clustering result will be statistically significant; the result of the statistically significant hierarchical structure tree can draw the conclusion that the generated associations are different from the randomly generated results, thus providing a validity basis for technical associations.

[0018] Optionally, the improved algorithm process based on agglomerative hierarchical clustering is as follows:

[0019] 1. Initialize an empty list p;

[0020] 2. for the number of clustering clusters k equals 2 to 100 do;

[0021] 3. Use the hierarchical clustering algorithm to generate a tree structure TD for the dataset D;

[0022] 4. Truncate TD according to the number of clustering clusters k to obtain the truncation height h1;

[0023] 5. for the variable i equals 1 to 1000 do;

[0024] 6. Generate a random dataset D' using the Bernoulli distribution, which has the same variance as D.

[0025] 7. Use the hierarchical clustering algorithm to generate a dendrogram TD' for the dataset D'.

[0026] 8. Truncate TD according to the number of clusters k to obtain the truncation height h2.

[0027] 9. Count the number of h2 ≤ h1, and store count / 1000 in P.

[0028] 10. Traverse the list p from the beginning until the first value less than 0.05 is found, and obtain the corresponding number of clusters kfinal. kfinal has statistical significance at the 95% confidence level.

[0029] Optionally, the process of applying clustering analysis to the ATT&CK dataset is divided according to the dissimilarity between each data. Therefore, the choice of the dissimilarity measurement criterion affects the clustering results. In applications, the clustering algorithm often uses the Euclidean distance in the feature space as the measurement criterion to calculate the dissimilarity between different samples. When using the Euclidean distance as the dissimilarity measurement, the smaller the distance between samples, the more similar they are and the more likely they are to be assigned to the same cluster. The similarity measurement (or distance measurement) used in clustering is performed on the sample data, so the similarity measurement method varies with the nature of the sample set. Since the ATT&CK dataset has discreteness, measurement methods other than the Euclidean distance need to be considered.

[0030] For the data in the ATT&CK dataset, it consists of binary variables. The Jaccard distance is an index used to measure the difference between two sets. The Jaccard distance is the complement of the Jaccard similarity coefficient and is defined as 1 minus the Jaccard similarity coefficient. The Jaccard similarity coefficient is an index used to measure the similarity between two sets.

[0031] Optionally, when used to calculate the Jaccard similarity coefficient between any two techniques T i and T j is defined as follows:

[0032]

[0033] Among them, the subscript of n needs to be two digits, representing whether T i and T j appear respectively. n 11 represents T i and T j appearing in the same APT attack instance, and n 01Representing T i Does not appear in a certain APT attack instance while T j The frequency of occurrence, n 10 And n 01 On the contrary, in the formula, the calculation of the Jaccard similarity coefficient does not consider the value of n 00 The Jaccard distance metric technique T i And T j The dissimilarity between them is defined as the complement of the Jaccard similarity system, that is, 1 - Js(T i , T j )); The Jaccard distance can be interpreted as the ratio of the intersection of the attack instances involved in T i And T j Divided by their union.

[0034] Optionally, the Phi coefficient is an empirical non - parametric correlation metric for binary data; when using the Phi coefficient to measure different technologies, first arrange the technologies to be measured into a 2×2 table, and the specific arrangement is shown in Table 4; the basic concept of the Phi coefficient is that if the observed values of two binary variables mostly fall in the main diagonal fields of the 2×2 contingency table, then these two technologies are positively correlated; conversely, if the observed values of two binary variables mostly fall in the non - diagonal fields, then these two variables are negatively correlated;

[0035] The Phi coefficient between any two technologies and its calculation method are as follows:

[0036]

[0037] On the basis of determining the distance metric method between samples, use Ward linkage as the cluster distance calculation method to establish an attack model.

[0038] The present invention provides a method for automatic orchestration of power grid attack resources, which has the following beneficial effects:

[0039] This method for automatic orchestration of power grid attack resources uses the OWL ontology description language to formally describe and represent the security state of the target system and attack resource information, realizing the unified knowledge representation of the target system, security vulnerabilities, attack processes, and attack resource information in the power system network; completely modeling the set of attack resources required for different types of atomic attacks, and obtaining the set of attack resources required at different stages and different nodes during the attack process through the analysis of the attack model, realizing the adaptation of attack resources to attack types; under the guidance of the attack strategy, introducing an execution path description language to depict the orchestration and encapsulation methods of the attack resources required during the attack execution process, developing an automatic attack resource orchestration engine to automatically realize the orchestration and encapsulation of power system network attack resources, and then achieving the purpose of automatically executing the penetration and attack on the target system using the encapsulated attack resources.

[0040] Based on the characteristics of APT attacks and defenses in existing new power system networks, and on the analysis of typical business types, attack processes, and means, some concepts in the existing network security ontology are reused, and the ATT&CK attack model and attack resources are introduced. A method for representing attack targets and resources based on ontology is proposed, and the dependency relationships among assets, vulnerabilities, attacks, and attack resources are constructed, as shown in Figure 3 the following; This method constructs an ontology model following a seven-step approach, determines the domain and scope of the power system network attack ontology. Since the power system network attack ontology model integrates assets, vulnerabilities, the ATT&CK attack model, and attack resources, ALVO (ATT&CK Link Vulnerability Ontology) is used to represent the network attack ontology; In the construction of the class set, to ensure the comprehensiveness of the constructed power system network ontology classes, an attacker class is introduced to describe all organizations that initiate attacks or pose threats; An asset class is introduced to describe all infrastructure in the network that may have vulnerabilities or defects; An attack result class is introduced to describe the impact of attacks on system integrity, availability, and confidentiality; An attack resource class is introduced to describe specific available attack tools; The Common Vulnerability Scoring System (CVSS) is introduced to evaluate the severity of vulnerabilities and indicate the urgency and importance of vulnerabilities; Further, the set of relationships between classes is constructed, and the construction of the network attack ontology is completed by combining the class set and the relationship set. Finally, the architecture of the network attack ontology ALVO is obtained, realizing the unified knowledge representation of target systems, security vulnerabilities, attack processes, and attack resource information in the power system network.

[0041] (1) Adapt the attack resources based on the attribute attack graph and attack model;

[0042] According to the target system and attack resource information represented by the power system network attack knowledge graph and historical log information, using the target system vulnerability information and the atomic attack resource information in the attack resources, based on the monotonicity assumption, an attribute attack graph is constructed; The attribute attack graph showing all possible attack paths in the system is optimized and pruned to obtain a set of effective attack paths; Based on the optimized attack graph model, a method for adapting attack resources is studied to obtain different types of attack resource sets required at different stages and nodes during the attack process, thus realizing the adaptation of attack resources to different types of attacks;

[0043] To accurately identify the attack resources required to achieve the goal, a method for adapting attack resources based on the attribute attack graph and attack model is studied, as shown in Figure 2As shown in the figure; based on the monotonicity assumption, this method fully considers the characteristics of the target system, vulnerability information, and attack resource information, and constructs an attribute attack graph to completely represent the set of attack paths for attacking the target system. The graph contains atomic attack nodes and attribute nodes. The atomic attack nodes represent a specific type of resource, while the attribute nodes describe the preconditions and attack results for the atomic attack nodes to carry out attacks. The edges between nodes also include two types: precondition edges and consequence edges. Further, aiming at the problems that the attack graph is often too large to accurately reflect the attack intention and may not be able to implement all possible attack paths shown in the attack graph due to attack resource limitations in actual application scenarios, a method for optimizing the attack graph based on the backward search strategy is studied. By using the depth-first search method, combined with information such as paths, jump points, vulnerabilities, and attack resources obtained from the ontology knowledge base, and taking the attack strategy and attack resource set as constraint conditions, effective attack paths are identified. Finally, a method for adapting attack resources based on Petri nets is proposed. By parsing the attack model, the sets of different types of attack resources required at different stages and nodes during the attack process can be accurately obtained. The attack model can be expressed in the following form: (attack state, attack resource set, relationship set), where: the attack state and attack resources need to meet the following conditions: 1) For the attack state, its input is the attack resource. If different attack resources can achieve the same attack state, these attack resources can be considered equivalent. 2) For the attack resources, its input is the attack state. If the same type of attack resources need to be triggered to execute, the input attack state must meet the set of input conditions that enable this type of attack resources to be executed. Executing the same type of attack resources for the input attack state will surely result in the same attack result. Finally, the adaptation of attack resources to attack targets and intentions is realized.

[0044] (2) Adopt an automatic orchestration method for attack resources based on the execution process description language;

[0045] Based on the attribute attack graph that describes the effective attack paths for attacking the target system and the attack resource adaptation method that determines the set of attack resources for implementing a specific attack, use a language similar to XML to describe the attack process, accurately depict the attack process, attack state, attack resources, and their mutual relationships for attacking the target system. Study an automatic orchestration engine for attack resources based on the attack execution process description language to realize the automatic orchestration and encapsulation of attack resources, and assist security personnel in selecting attack resources for orchestration and encapsulation based on the visual interface.

[0046] Use an attack execution process description language customized based on XML to describe the attack paths implemented during the attack, the dependencies between the node attack states and attack resources, and generate an attack execution process description file. On this basis, design an attack resource automatic orchestration engine based on the attack execution process description language, and automatically translate the attack execution process description file into an executable file that generates an attack execution program package under the guidance of the attack strategy to achieve the orchestration and encapsulation of attack resources; at the same time, provide a visual editing environment to assist security personnel in configuring, managing, orchestrating, and scheduling attack targets, strategies, paths, methods, and attack resources; after completing the attack execution process orchestration, use the execution process description language to represent the orchestrated attack execution process and generate the final attack execution process described in this language.

[0047] As Figure 1 shown,

[0048] ① The attack execution process description language describes the attack paths implemented during the attack and the relationships between the node attack states and attack resources in the attack paths in an accurate and concise manner, which is the basis for realizing the automatic orchestration of attack resources; since the attack graph describes the effective attack paths for attacking the target system, and the adaptation method of the attack model and attack resources determines the set of attack resources for implementing a specific attack, therefore, by using the execution process description language, the attack process, attack states, attack resources, and their mutual relationships for attacking the target system can be accurately characterized.

[0049] The Extensible Markup Language (XML) is used to mark electronic files to make them structured; the XML language allows users to perform data marking, data type definition, and allows users to create their own markup languages and provides a unified way to describe structured data; since XML files can clearly describe the mutual relationships and related attribute information between the attack process, attack states, and attack resources during the attack, and at the same time, its parsing function is also convenient for guiding the attack on the target system by combining attack resources based on the attribute attack graph, therefore, a class XML language can be used as the attack execution process description language to describe and parse the attack graph and attack resources.

[0050] ② The attack resource automatic orchestration engine based on the attack execution process description language studies the attack resource automatic orchestration engine, so that it can, under the guidance of the attack strategy, achieve the orchestration and encapsulation of the attack resources required during the attack execution process described by the execution path description language, and use the encapsulated attack resources to automatically execute the penetration and attack on the target system.

[0051] Since the attack execution process description language is represented by an interpreted language, and the interpreted language has good process description capabilities, the attack resource automated orchestration engine can realize the automated orchestration of attack resources according to the attribute attack graph and its attack execution process representation; the attack resource automated orchestration engine can not only automatically realize the orchestration and encapsulation of attack resources, but also assist security personnel in selecting attack resources for orchestration and encapsulation based on the visual interface;

[0052] ③ Visualization of the attack execution process orchestration. The visualization method of the attack execution process and the attack resource orchestration helps to realize the visual configuration and editing of attack goals, strategies, paths, methods, and the attack resource set, and assist security personnel in optimizing the configuration; Graph_viz (Graph_Visualization_Software) can be used to draw the graph described by the DOT language script; Graph_viz consists of a graph description language called the DOT language and a set of tools that can generate and / or process DOT files. The DOT text graph description language provides a simple graph description method; therefore, in order to realize the visual orchestration of the attack execution process, Graph_viz is used to realize the visual orchestration of the attack execution process in the attack graph.

[0053] Comprehensively applying the above key technologies, design and implement a conceptual prototype of network attack resource automatic orchestration, and realize functions such as attack target and attack resource representation, attack path generation, attack process modeling, attack resource automated orchestration, and attack process visualization, and support the generation of attack task packages in typical Windows and Linux environments. Brief Description of the Drawings

[0054] Figure 1 It is a schematic diagram of the attack resource automatic orchestration work process based on the execution process description language of the present invention;

[0055] Figure 2 It is a resource adaptation flow chart based on the attribute attack graph and attack model of the present invention;

[0056] Figure 3 It is a schematic diagram of the attack target and resource representation structure based on ontology of the present invention. Detailed Embodiments

[0057] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0058] In the description of the present invention, unless otherwise specified, "a plurality of" means two or more; the orientation or positional relationship indicated by terms such as "upper", "lower", "left", "right", "inner", "outer", "front end", "rear end", "head", "tail", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be construed as a limitation on the present invention. In addition, terms such as "first", "second", "third", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.

[0059] In the description of the present invention, it should be noted that, unless otherwise clearly specified and defined, the terms "connected" and "coupled" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0060] Please refer to Figures 1 to 3 , the present invention provides a technical solution: an automatic orchestration method for power grid attack resources, which is specifically as follows:

[0061] S1. The attack execution process description language describes the attack paths implemented during the attack, as well as the relationship between the node attack states and attack resources in the attack paths, in an accurate and concise manner. Since the attack graph describes the effective attack paths for attacking the target system, and the adaptation method of the attack model and attack resources determines the set of attack resources for implementing a specific attack, an execution process description language is adopted to accurately depict the attack process, attack states, attack resources and their mutual relationships for attacking the target system; among them, the Extensible Markup Language (XML) is used for implementation. The Extensible Markup Language (XML) is used to mark electronic files to make them structured; the XML language allows users to perform data marking, data type definition, and allows users to create their own markup languages, and provides a unified way to describe structured data; since the XML file can clearly describe the mutual relationships and related attribute information among the attack process, attack states, and attack resources, and at the same time, its parsing function is also convenient for guiding the attack on the target system by combining attack resources based on the attribute attack graph, therefore, a class XML language is adopted as the attack execution process description language to describe and parse the attack graph and attack resources;

[0062] S2. Attack resource automated orchestration engine based on the attack execution process description language. Research the attack resource automated orchestration engine to enable it to, under the guidance of attack strategies, achieve the orchestration and encapsulation of attack resources required in the attack execution process described by the execution path description language, and use the encapsulated attack resources to automatically execute the penetration exploitation and attack on the target system. Since the attack execution process description language is represented by an interpretive language, and the interpretive language has the ability to describe processes, the attack resource automated orchestration engine realizes the automated orchestration of attack resources according to the attribute attack graph and its attack execution process representation.

[0063] S3. Visualization of attack execution process orchestration. The visualization method of the attack execution process and attack resource orchestration helps to achieve the visual configuration and editing of attack goals, strategies, paths, methods, and the attack resource set, and assist security personnel in optimizing the configuration. Among them, Graphviz (Graph Visualization Software) is used for the operation. Graphviz is used to draw graphs described by DOT language scripts. Graphviz consists of a graph description language called the DOT language and a set of tools for generating and / or processing DOT files. Therefore, in order to achieve the visual orchestration of the attack execution process, Graphviz is used to implement the visual orchestration of the attack execution process in the attack graph.

[0064] Among them,

[0065] For the power system network, construct a unified representation of attack goals and resources based on ontology. On the basis of comprehensively analyzing power system network devices and systems, vulnerabilities, attacks, and attack resources, propose a method for constructing a network attack ontology model that integrates the ATT&CK attack model for the power system network. By jointly modeling the target system, vulnerabilities, attack models, and attack resources, realize the association and integration of discrete system and vulnerability information and corresponding attack means, and then construct a network attack knowledge graph to achieve the unified representation of power system network attack goals and attack resources based on ontology.

[0066] First, quantify the clustering object ATT&CK technology set to provide a data basis for the clustering algorithm. The technologies in the ATT&CK model are all text data, which need to be converted into a vector data set before being applied to the clustering algorithm. MITRE organizes the text descriptions of technologies according to the relevant fields provided in Table 1 (only some fields are listed in the table). Although the descriptions of technologies are structurally organized as a whole, the text content within different fields is unstructured and affected by factors such as the writing style of the author. Referring to Table 1, it can be seen that most of the data related to technologies consists of text. Therefore, when considering the quantification method, first consider directly quantifying the text data, and adopt the common processing steps in the field of natural language processing to perform word segmentation, quantification, etc. on the text data. There are two deficiencies in quantifying using the above method. First, the text descriptions of different technologies are greatly affected by the subjective factors of their authors. Second, when directly performing word segmentation and quantification, since the lengths of different texts are different, the dimensions of the obtained feature vectors are also different. Truncating or padding different vector dimensions may result in the loss of some information during the implementation process. Considering the above deficiencies, in the present invention, the Groups knowledge base also provided by MITRE is used to complete the quantification of the technology data set.

[0067] Table 1 Technical Introduction in the ATT&CK Model

[0068]

[0069] Groups is used to organize publicly available intrusion intelligence on the Internet. Its role and contribution are to determine a common and unified name in the security community for tracking intrusion activities. Analysts use various analysis methods and terms to track activity clusters, such as threat groups, threat actors, and intrusion collective activities.

[0070] Table 2 Attack Instance Descriptions in Groups

[0071]

[0072] During the quantification process, the present invention uses the technology / sub-technology fields in Table 2. In the Groups knowledge base, each APT record is regarded as an attack instance, and each technology is regarded as a constituent attribute of the attack instance.

[0073] The present invention adopts the binary coding method in feature engineering; binary coding is a commonly used and easy-to-operate quantization method. It determines whether a certain feature exists or not, and then decides whether the corresponding position in the feature vector is 1 or 0, rather than quantifying the occurrence times. With the help of the Groups knowledge base, the techniques in the ATT&CK model are uniformly mapped to 81-dimensional vectors. The mapping strategy is that each dimension in the vector represents an attack instance in Groups. If the technique is used in the attack instance, the value of this dimension is 1, otherwise it is 0. After being processed by the above mapping method, the data set consists of discrete high-dimensional vectors, and the result of the feature is 0 or 1, which respectively represent the negative or positive occurrence of a certain technique in the attack instance. During the process of quantifying using the Groups knowledge base, in order to avoid generating misleading technical associations, the present invention uses attack instances containing at least five different techniques for quantization. In the following part of this section, the vector data set obtained by quantifying the ATT&CK technique set is simply referred to as the ATT&CK data set;

[0074] The technique set of the ATT&CK attack model adopts the agglomerative hierarchical clustering algorithm, and a statistical hypothesis testing step is added to the clustering process. With the help of the statistical hypothesis testing results, the validity of the clustering results is verified, and the optimal number of clusters is determined at the same time. The null hypothesis verification adopted in the statistical hypothesis testing step uses a part of the data analysis experiment, which means that a hypothesis is established in advance when conducting a statistical test. When the null hypothesis holds, the relevant statistic should follow a known probability distribution. When the calculated value of the statistic falls into the rejection region;

[0075] Combining the statistical hypothesis testing with the clustering algorithm, comparing the tree structure generated by the ATT&CK data set with the tree generated by the null distribution to analyze the effectiveness of the clustering, and allowing to infer statistically significant results at the required confidence level. The data set used for the statistical hypothesis testing is generated by a random Bernoulli distribution, and the generated data has the same variance as the ATT&CK data set. The empty tree generated on the random data set is denoted as T0; if the number of clusters in the specified stage height TD is significantly different from the number of clusters in T0, the clustering result will be statistically significant; the result of the hierarchical structure tree with statistical significance can draw the conclusion that the generated association is different from the randomly generated result, thus providing a validity basis for technical associations;

[0076] The improved algorithm process based on agglomerative hierarchical clustering is as follows:

[0077] 1. Initialize an empty list p;

[0078] 2. for the number of clustering clusters k from 2 to 100 do;

[0079] 3. Use the hierarchical clustering algorithm to generate a tree structure TD for the data set D;

[0080] 4. Truncate TD according to the number of clustering clusters k to obtain the truncation height h1;

[0081] 5. For variable i equal to 1 to 1000 do;

[0082] 6. Generate a random data set D' using the Bernoulli distribution, which has the same variance as D;

[0083] 7. Use the hierarchical clustering algorithm to generate a tree structure TD' for the data set D';

[0084] 8. Truncate TD according to the number of clustering clusters k to obtain the truncation height h2;

[0085] 9. Count the number of h2 ≤ h1 as count, and store count / 1000 into P;

[0086] 10. Traverse the list p from the beginning until the first value less than 0.05 is found, and obtain the corresponding number of clusters kfinal. kfinal has statistical significance at the 95% confidence level;

[0087] The process of applying cluster analysis to the ATT&CK data set is to divide according to the dissimilarity between each data. Therefore, the selection of the dissimilarity measurement standard has an impact on the clustering result; in the application, the clustering algorithm mostly uses the Euclidean distance in the feature space as the measurement standard to calculate the dissimilarity between different samples; when using the Euclidean distance as the dissimilarity measurement, the smaller the distance between samples, the more similar the two are, and the more likely they are to be divided into the same cluster; the similarity measurement (or distance measurement) used in clustering is performed on the sample data, so the similarity measurement method varies with the nature of the sample set; due to the discreteness of the ATT&CK data set, it is necessary to consider measurement methods other than the Euclidean distance;

[0088] The data of the ATT&CK data set consists of binary variables; the Jaccard distance is an index used to measure the difference between two sets. The Jaccard distance is the complement of the Jaccard similarity coefficient and is defined as 1 minus the Jaccard similarity coefficient. The Jaccard similarity coefficient is an index used to measure the similarity between two sets;

[0089] When used to calculate the Jaccard similarity coefficient between any two techniques T i and T j is defined as follows:

[0090]

[0091] Among them, the subscript of n needs to be two digits, representing whether T i and T j appear respectively from left to right, n11 Representing T i and T j The frequency of appearance in the same APT attack instance, n 01 Representing T i Not appearing in a certain APT attack instance while T j The frequency of appearance, n 10 And n 01 Is defined conversely, and the calculation of the Jaccard similarity coefficient in the formula does not consider the value of n 00 The value; the Jaccard distance measures the dissimilarity between techniques T i and T j And is defined as the complement of the Jaccard similarity system, that is, 1 - Js(T i , T j ); the Jaccard distance can be interpreted as the ratio of the intersection of the attack instances involved by T i and T j Divided by the ratio of their union;

[0092] The Phi coefficient is an empirical non-parametric correlation measure for binary data; when using the Phi coefficient to measure different techniques, first arrange the techniques to be measured into a 2×2 table, and the specific arrangement is shown in Table 4; the basic concept of the Phi coefficient is that if the observed values of two binary variables mostly fall in the main diagonal fields of the 2×2 contingency table, then these two techniques are positively correlated; conversely, if the observed values of two binary variables mostly fall in the non-diagonal fields, then these two variables are negatively correlated;

[0093] The calculation method of the Phi coefficient between any two techniques is as follows:

[0094]

[0095]

[0096] On the basis of determining the distance measurement method between samples, use Ward linkage as the cluster distance calculation method to establish an attack model.

[0097] As described above, it is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. An automatic orchestration method for power grid attack resources, characterized in that, The details are as follows: S1. The attack execution process description language describes the attack paths implemented during the attack in an accurate and concise manner, as well as the relationship between the node attack states and attack resources in the attack paths. Since the attack graph describes the effective attack paths for attacking the target system, and the adaptation method of the attack model and attack resources determines the set of attack resources for implementing a specific attack, the execution process description language is adopted to accurately depict the attack process, attack states, attack resources and their mutual relationships for attacking the target system; among which, the extensible markup language is used to implement the operations; S2. The attack resource automated orchestration engine based on the attack execution process description language studies the attack resource automated orchestration engine to enable it to realize the orchestration and encapsulation of the attack resources required during the attack execution process described by the execution path description language under the guidance of the attack strategy, and automatically execute the penetration exploitation and attack on the target system using the encapsulated attack resources; since the attack execution process description language is represented by an interpretive language, and the interpretive language has the ability to describe processes, the attack resource automated orchestration engine realizes the automated orchestration of attack resources according to the attribute attack graph and its attack execution process representation; S3. Visualization of the attack execution process orchestration. The visualization method of the attack execution process and attack resource orchestration helps to realize the visual configuration and editing of the attack objectives, strategies, paths, methods and attack resource sets, and assist security personnel in optimizing the configuration; among which, Graphviz is used to implement the operations. Graphviz is used to draw the graphs described by the DOT language scripts; Graphviz consists of a graph description language called the DOT language and a set of tools for generating and / or processing DOT files; therefore, in order to realize the visual orchestration of the attack execution process, Graphviz is used to realize the visual orchestration of the attack execution process in the attack graph; Among them, For the power system network, a unified representation of attack objectives and resources based on ontology is constructed. On the basis of comprehensively analyzing the power system network devices and systems, vulnerabilities, attacks and attack resources, a method for constructing a network attack ontology model integrating the ATT&CK attack model for the power system network is proposed. By jointly modeling the target system, vulnerabilities, attack models and attack resources, the association and integration of discrete system and vulnerability information and corresponding attack means are realized, and then a network attack knowledge graph is constructed to realize the unified representation of power system network attack objectives and attack resources based on ontology.

2. The automatic orchestration method of power grid attack resources according to claim 1, characterized in that: In S1, the Extensible Markup Language is used to mark electronic files to make them structured; the XML language allows users to perform data marking, data type definition, and allows users to create their own markup languages, and provides a unified way to describe structured data; since XML files can clearly describe the mutual relationships and related attribute information among the attack process, attack status, and attack resources during an attack, and at the same time, its parsing function is also convenient to realize the guided attack on the target system based on the attribute attack graph and combined with attack resources, therefore, a class of XML language is used as the attack execution process description language to describe and parse the attack graph and attack resources.

3. The automatic orchestration method of power grid attack resources according to claim 1, wherein: The technology set of the ATT&CK attack model adopts the agglomerative hierarchical clustering algorithm, and a statistical hypothesis testing step is added to the clustering process. With the help of the statistical hypothesis testing results, the validity of the clustering results is verified, and at the same time, the optimal number of clusters is determined. The null hypothesis verification adopted in the statistical hypothesis testing step uses a part of the data analysis experiment, which means that a hypothesis is established in advance when conducting a statistical test. When the null hypothesis holds, the relevant statistic should follow a known probability distribution, and when the calculated value of the statistic falls into the rejection region; The statistical hypothesis testing is combined with the clustering algorithm. The tree structure generated by the ATT&CK dataset is compared with the tree generated by the null distribution to analyze the effectiveness of the clustering, and it is allowed to infer statistically significant results at the required confidence level. The dataset used for the statistical hypothesis testing is generated by a random Bernoulli distribution, and the generated data has the same variance as the ATT&CK dataset. The empty tree generated on the random dataset is denoted as T0; if the number of clusters in the specified stage height TD is significantly different from the number of clusters in T0, the clustering result will be statistically significant; the result of the statistically significant hierarchical structure tree can draw the conclusion that the generated association is different from the randomly generated result, thus providing a validity basis for the technical association.

4. The automatic orchestration method of power grid attack resources according to claim 3, characterized in that: The improved algorithm based on agglomerative hierarchical clustering is as follows:

1. Initialize an empty list p; 2. for the number of clustering clusters k from 2 to 100 do; 3. Use the hierarchical clustering algorithm to generate a tree structure TD for the dataset D; 4. Truncate TD according to the number of clustering clusters k to obtain the truncation height h1; 5. for the variable i from 1 to 1000 do; 6. Use the Bernoulli distribution to generate a random dataset D' with the same variance as D; 7. Use the hierarchical clustering algorithm to generate a tree structure TD' for the dataset D'; 8. Truncate TD' according to the number of clustering clusters k to obtain the truncation height h2; 9. Count the number count of h2 ≤ h1, and store count / 1000 into P; 10. Traverse the list p from the beginning until the first value less than 0.05 is found, and obtain the corresponding number of clusters kfinal. kfinal is statistically significant at the 95% confidence level.

5. The automatic orchestration method of power grid attack resources according to claim 1, characterized in that: The process of applying clustering analysis to the ATT&CK dataset is divided according to the dissimilarity between each data. Therefore, the selection of the dissimilarity metric has an impact on the clustering results. In applications, clustering algorithms mostly use the Euclidean distance in the feature space as the metric to calculate the dissimilarity between different samples. When using the Euclidean distance as the dissimilarity measure, the smaller the distance between samples, the more similar they are and the more likely they are to be assigned to the same cluster. The similarity metric used in clustering is executed on the sample data, so the similarity metric method varies with the nature of the sample set. Since the ATT&CK dataset has discreteness, it is necessary to consider metrics other than the Euclidean distance. The data of the ATT&CK dataset consists of binary variables. The Jaccard distance is an index used to measure the difference between two sets. The Jaccard distance is the complement of the Jaccard similarity coefficient, which is defined as 1 minus the Jaccard similarity coefficient. The Jaccard similarity coefficient is an index used to measure the similarity between two sets.

6. The automatic orchestration method of power grid attack resources according to claim 1, characterized in that: When calculating the Jaccard similarity coefficient between any two technologies T i and T j it is defined as follows: Among them, the subscript of n needs to be two digits, representing T from left to right i and T j whether they appear or not, n 11 represents T i and T j the frequency of their appearance in the same APT attack instance, n 01 represents T i not appearing in a certain APT attack instance while T j appears, n 10 is defined oppositely to n 01 and is not considered in the calculation of the Jaccard similarity coefficient in the formula 00 the value of; The Jaccard distance metric technology T i and T j the dissimilarity between them, and is defined as the complement of the Jaccard similarity system, that is, 1 - Js(T i , T j ); The Jaccard distance can be interpreted as the ratio of the intersection of the attack instances involved in T i and T j divided by their union.

7. The automatic orchestration method of power grid attack resources according to claim 1, characterized in that: The Phi coefficient is an empirical non-parametric correlation metric for binary data. When using the Phi coefficient to measure different techniques, the techniques to be measured are first arranged in a 2×2 table, and the specific arrangement is shown in Table 4. The basic concept of the Phi coefficient is that if the observed values of two binary variables mostly fall in the main diagonal fields of the 2×2 contingency table, then these two techniques are positively correlated; conversely, if the observed values of two binary variables mostly fall in the non-diagonal fields, then these two variables are negatively correlated. The Phi coefficient and its calculation method between any two techniques are as follows: Based on determining the distance metric method between samples, Ward linkage is used as the method for calculating the cluster distance to establish an attack model.

Citation Information

Patent Citations

  • Security arrangement and automatic response method, device and system aiming at APT attack

    CN114070629A

  • SOAR-based defense automation process arrangement method

    CN115442133A

  • Network security intelligent decision automatic arrangement response method and system

    CN116318818A