High-accuracy threat intelligence assisted network threat tracing method

By combining the optimization Transformer network model with the Black Swan optimization algorithm, efficient fusion of multimodal data and precise reconstruction of attack paths are achieved, the problem of insufficient fusion of multimodal data in the existing technology is solved, and the accuracy and robustness of network threat tracing are improved.

CN120301682APending Publication Date: 2025-07-11GUANGXI POWER GRID CORP
View PDF 0 Cites 13 Cited by

Patent Information

Application Number
CN202510613856.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

When facing large-scale heterogeneous data sources, multi-stage attack chains and cross-modal intelligence information, existing network threat traceability technologies lack multi-modal data fusion mechanisms, resulting in incomplete semantic expression of attack behavior, low accuracy of path reconstruction, and difficult parameter configuration to adapt to complex network attack environments, and insufficient model generalization capabilities.

Method used

The optimized Transformer network model and the Black Swan optimization algorithm are adopted, combined with the multimodal attack behavior modeling mechanism and semantic-driven attack path reconstruction strategy, and precise traceability is achieved through context-aware modeling, intelligence vector embedding and path dependency calculation.

Benefits of technology

It improves the accuracy and robustness of network threat tracing, can efficiently track attack source nodes in complex multi-stage attack environments, and enhances the modeling ability of multi-hop and cross-stage attack paths and the recognition accuracy of rare attack behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301682A_ABST
    Figure CN120301682A_ABST
Patent Text Reader

Abstract

The invention discloses a high-accuracy threat intelligence assisted network threat tracing method, which comprises the following steps: S1, collecting and preprocessing multi-source network security data, and constructing a time-marked event sequence set; s2, constructing an optimized Transform network model, and processing an attack event sequence by using position coding and time embedding; s3, a black swan optimization algorithm is initialized, and a Transform structure hyper-parameter is dynamically optimized; s4, outputting an attack event semantic vector, and constructing an attack path semantic map; s5, the intelligence information vector is embedded into a Transform hidden space; s6, calculating semantic similarity and dependency intensity, and generating an attack source candidate set and a traceability path; s7, outputting an attack traceability path, a starting point node and an information label, and generating a structured traceability report; and S8, according to the traceability result feedback, updating the black swan algorithm and the Transform model. The method is used for realizing intelligent modeling of multi-source network attack events and high-accuracy traceability analysis of attack source nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of network security and artificial intelligence, and particularly to a network threat tracing method assisted by high-accuracy threat intelligence. Background Art

[0002] With the continuous improvement of the complexity and openness of network information systems, the concealment, multi-stage nature, and intelligence level of various network attack behaviors have become increasingly profound. Traditional network defense means based on rules or feature matching are difficult to meet the detection and tracking requirements of complex security events such as new advanced persistent threats (APTs), multi-hop attack chains, and zero-day attacks. In this context, network threat tracing, as an important security technology for tracing the source of attacks, reconstructing attack chains, restoring attack paths, and assisting in emergency response, has gradually become the core research direction in the field of network security.

[0003] Currently, most mainstream network threat tracing technologies rely on means such as log backtracking, traffic replay, and topology reconstruction. By analyzing the changes in network behaviors and communication links before and after attack events occur, they attempt to locate the source node of the attack and restore the attack process. These methods have certain effects in static attack models and scenarios with clear rules, but in the face of large-scale heterogeneous data sources, multi-stage attack chains, multi-hop paths, and cross-modal intelligence information, traditional methods expose significant technical shortcomings. First, most existing tracing systems rely on a single data source in the modeling stage, such as network logs, host logs, or traffic information, lacking a fusion mechanism for multi-modal and multi-source data, resulting in incomplete semantic expressions of attack behaviors, and thus affecting the tracing accuracy. Second, in attack path recognition, traditional methods mostly use fixed template matching, time sliding windows, or heuristic analysis, and are unable to effectively identify complex cross-hop behaviors or phased mutation behaviors existing in the path. Especially when facing situations such as sparse attack paths, discontinuous nodes, and heterogeneous behavior patterns, the accuracy of path reconstruction drops significantly. In addition, existing methods generally lack a context awareness mechanism and dynamic learning ability, cannot adapt to the characteristics of network threat behaviors that change over time, and are difficult to achieve generalization recognition of unknown attacks through historical behaviors.

[0004] In recent years, the introduction of artificial intelligence technology, especially deep learning, into the field of network security has provided new solutions for network threat modeling and traceability analysis. Among them, the Transformer model, as a sequence modeling structure centered on the multi-head self-attention mechanism, has powerful context modeling capabilities and global dependency capture capabilities, and has been widely used in natural language processing, image recognition, behavior prediction and other fields. Applying the Transformer model to the representation learning of attack event sequences is expected to break the dependence limitation of traditional methods on temporal logic and achieve semantic modeling of behavior nodes in complex attack paths. However, in actual scenarios, due to the characteristics of strong heterogeneity, scarce behavior samples, and rapid changes in attack chain patterns in network attack event data, parameter configurations in the Transformer structure, such as the number of layers, the number of attention heads, and the hidden dimension, have a great impact on the model performance. If static configurations are adopted, it is easy to cause the model to be underfitted or overfitted, restricting its adaptability and generalization ability in diverse attack environments.

[0005] At the same time, threat intelligence, as a key resource in network security in recent years, contains rich context information such as attacker profiles, TTP (Tactics, Techniques and Procedures), and IOC (Indicators of Compromise), and is an important clue source for identifying and tracing attacks. However, existing research often introduces threat intelligence as independent reference data into the post-processing link of traceability, lacking a mechanism for deeply integrating intelligence semantic information with the semantic space of attack paths, resulting in the inability of intelligence information to effectively intervene in the path modeling process, and thus unable to improve the semantic expression ability of attack path nodes and the accuracy of path completion. In the process of traceability, how to embed structured intelligence fields, unstructured TTP descriptions, and fuzzy behavior clues into the model learning process is still one of the key difficulties in the existing technology.

[0006] In addition, due to the large size and numerous parameters of the Transformer network structure, it is difficult to obtain the best model structure configuration relying solely on manual experience or traditional parameter tuning methods when facing complex data features and diverse intelligence fusion requirements in the real attack environment. There is a lack of an effective global structure parameter optimization mechanism in the existing technology. Especially under the simultaneous constraints of multi-dimensional objectives (such as rare behavior recognition, path connectivity, computational complexity), the parameter tuning efficiency of the Transformer is low and the accuracy is unstable. Some research introduces classical intelligent optimization algorithms such as genetic algorithms and particle swarms, but it is still difficult to adapt to the network attack sample space with rare perturbations, high impact costs, and behavior mutations.

[0007] Therefore, how to provide a network threat traceability method assisted by high-accuracy threat intelligence is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0008] An object of the present invention is to propose a network threat tracing method assisted by high-accuracy threat intelligence. The present invention integrates an optimized Transformer network model and a black swan optimization algorithm, constructs a multi-modal attack behavior modeling mechanism and a semantics-driven attack path reconstruction strategy, and details the whole process of accurate tracing through key steps such as context-aware modeling, intelligence vector embedding, path dependence calculation, and source node intelligent identification. This method has the advantages of high modeling accuracy, deep intelligence integration, strong integrity of the tracing path, and strong ability to identify sudden attack behaviors, and is applicable to efficient tracking and security response in complex multi-stage network attack environments.

[0009] A network threat tracing method assisted by high-accuracy threat intelligence according to an embodiment of the present invention includes the following steps:

[0010] S1. Collect multi-source network security data, preprocess the multi-source network security data, and construct a time-stamped data sequence set;

[0011] S2. Construct a Transformer network model, encode the attack events in the data sequence set into a Token sequence, input it into the Transformer network model, and process the timing information by using a position encoding and time embedding mechanism;

[0012] S3. Initialize the population parameters of the black swan optimization algorithm, and dynamically optimize the structural hyperparameters of the Transformer network model through the black swan optimization algorithm;

[0013] S4. Apply the optimized Transformer network model to the attack event sequence data, output an event-level context semantic vector, construct an attack path semantic graph, and establish upstream and downstream attack relationship connections between nodes;

[0014] S5. Vectorize the attack features, attack indicators, and attacker tactics, techniques, and procedures (TTP) information in the threat intelligence information, embed them into the latent space output by the optimized Transformer network model, and perform joint calculations with the attack path semantic vectors to complete the semantic enhancement and complementation of the attack path nodes;

[0015] S6. According to the similarity relationship between the event vectors and the embedded intelligence vectors in the attack path semantic graph, calculate the candidate set of attack source nodes through path propagation metrics and upstream and downstream dependence strengths, generate a tracing path, and locate the attack starting point;

[0016] S7. Output the generated attack tracing path, attack starting point node information, threat intelligence features, and attack organization portrait information, and generate a structured tracing report;

[0017] S8. Update the fitness evaluation mechanism of the individuals in the black swan optimization algorithm population according to the structured traceability report, and re-optimize the parameters of the Transformer network model to construct a dynamic adaptive iterative optimization mechanism.

[0018] Optionally, the multi-source network security data specifically includes network communication logs, host behavior logs, and threat intelligence data, which are used to support the modeling of attack event sequences and the semantic analysis of attack paths.

[0019] Optionally, the preprocessing of the multi-source network security data specifically includes format standardization, time alignment, and noise removal, which are used to construct an input sequence of attack events with consistent time series and available for the Transformer network model to learn.

[0020] Optionally, S2 specifically includes:

[0021] S21. Represent the constructed time-tagged data sequence set as an input sequence set where each item X t represents the t-th attack event feature vector;

[0022] S22. For each event input X t , generate a multi-scale attack context-aware position encoding vector where, is a dynamic encoding vector based on the event time difference, is an attack phase label embedding vector, is the hop number embedding vector between the event and the nearest threat intelligence hit event, and the three are used to jointly express the attack context position information;

[0023] S23. Define the embedding representation of each event as E t =X t +P t , and form an input sequence with enhanced position

[0024] S24. Construct a Transformer network model as the attack event modeling structure, and the Transformer network model is controlled by the following three innovative structural hyperparameters:

[0025] d align : The cross-modal shared attention alignment dimension, which is used to control the interaction representation dimension between the behavior modality and the intelligence modality;

[0026] r jump : The hop number attention diffusion coefficient, which is used to adjust the contribution ratio of nodes with different hop numbers in the path attention calculation;

[0027] s​​mask : Phase-guided attention mask strategy switch parameter, used to enable or disable the attention constraint mechanism guided by the attack phase;

[0028] S25. Input the position-enhanced input sequence into the Transformer model, and perform multi-head self-attention mechanism, residual connection, and feed-forward network operations on each layer to output a sequence of context semantic feature vectors for attack path modeling.

[0029] Optionally, the specific content of S3 includes:

[0030] S31. Construct a population set of the black swan optimization algorithm Each individual represents three structural innovation parameters to be optimized in the Transformer network structure, where d align is the cross-modal shared attention alignment dimension, r jump is the hop number attention diffusion coefficient, s mask is the phase-guided attention mask strategy switch parameter;

[0031] S32. Define the search boundary of the individual parameters as:

[0032]

[0033] Among them, when , enable the phase label multi-head hierarchical mask mechanism. The enabling of the phase label multi-head hierarchical mask mechanism specifically means that in the multi-head self-attention module of the Transformer network model, a mask matrix constructed based on the attack phase label is introduced for each attention head, so that each attention head calculates the attention weight only within a specific attack phase or between related phases, realizing the hierarchical attention and modeling of different heads for the features of different attack phases, and improving the semantic expression ability and path association accuracy of the Transformer network model for multi-stage attack chains;

[0034] S33. Introduce the behavior memory-guided perturbation mechanism and rare behavior reinforcement selection mechanism in the black swan optimization algorithm, and perform jump perturbation on the current individual x i to generate a candidate individual satisfying:

[0035]

[0036] Among them, λ i is the jump perturbation amplitude factor, ξ i is the uniform random perturbation, ρ i is the rare behavior response coefficient, M i is the historical winning memory perturbation vector constructed based on the feedback of rare attack samples;

[0037] S34. Apply the candidate individuals to the Transformer model structure to train the attack behavior sequence and calculate the fitness function

[0038]

[0039] where Acc rare represents the classification accuracy of the Transformer model for low-frequency attack events, F1 overall represents the overall F1 score, Div path represents the deviation penalty term for attack path generation, and α, β, θ are control coefficients;

[0040] S35. Select the optimal individuals in the next-generation population using the rare sample first strategy. If the optimal individuals have stable performance in multiple rare behavior distribution regions, increase the perturbation replication weight;

[0041] S36. Determine whether the termination condition is met. If it is met, output the optimal individuals; otherwise, return to S33 to continue the optimization iteration process.

[0042] Optionally, the S4 specifically includes:

[0043] S41. Based on the optimized Transformer network model, perform inference on the attack event sequence to obtain the context semantic representation vectors of each event node, and at the same time extract the corresponding context state labels of the nodes, including the attack stage identifier, semantic mutation degree, and model confidence, for constructing the multi-dimensional semantic label set of the graph nodes;

[0044] S42. According to the dynamic matching result of the similarity between the order of event nodes on the time axis and the semantic representation, construct the basic connection edge set, and perform structure completion according to the behavior labels of the nodes and the upstream and downstream stage transition relationships to form the initial attack behavior graph structure;

[0045] S43. Introduce a dynamic weight decay function for all edges in the graph, comprehensively calculate the edge weights based on the hop count, intelligence similarity, and stage inconsistency, and generate an adjustable upstream and downstream propagation probability matrix for controlling the path credibility mapping strategy;

[0046] S44. Introduce a rare behavior detection module to label the events with low model recognition confidence and significantly deviated behavior characteristics among the event nodes, and establish a "rare behavior key node marking layer", which is used as an overlay sub-structure for path priority analysis in the graph;

[0047] S45. Introduce a cross-modal edge enhancement mechanism to establish a semantic auxiliary connection between the structured attack event nodes and the hit nodes in the unstructured threat intelligence vector, forming an intelligence-driven auxiliary edge set to strengthen the information jump void area in the path;

[0048] S46. After completing the graph structure optimization, perform structure normalization processing on the attack path graph, including redundant edge pruning, graph structure sparsification, and semantic role classification reconstruction, and finally output an attack path semantic graph with stage awareness, path stability, and semantic consistency.

[0049] Optionally, the specific steps of S5 are as follows:

[0050] S51. Extract threat intelligence data related to attack behaviors, including attack feature fields, attack indicator entries, attack organization identifiers, and corresponding tactics, techniques, and procedures information, and perform structure cleaning and semantic standardization processing on the threat intelligence data;

[0051] S52. Perform multi-channel embedding processing on the preprocessed threat intelligence data, encode the structured fields, TTP tags, and unstructured texts respectively to generate a unified format set of intelligence vectors as the cross-modal semantic information source;

[0052] S53. Embed the intelligence vectors into the hidden space dimension corresponding to the output of the optimized Transformer network model, construct an aligned intelligence vector set that matches the context semantic representation of the attack path nodes, and introduce stage labels and confidence factors for intelligence screening;

[0053] S54. Perform joint attention calculation on the semantic vectors of the attack path nodes output by the optimized Transformer network model and the aligned intelligence vectors, establish a semantic similarity mapping relationship, and determine the high-correlation pairing between the nodes and the intelligence;

[0054] S55. For the attack nodes that do not directly hit the intelligence entries, infer and supplement the missing behavior labels, attack stages, or TTP information based on the high semantic similarity relationship between the intelligence vectors and the context features, and achieve semantic enhancement and context completion of the node attributes;

[0055] S56. Write the completed node semantic attributes into the attack path semantic graph, update the semantic descriptions and classification labels of each node in the graph, complete the enhancement of the graph structure at the semantic level and the improvement of the path content, and improve the accuracy and integrity of the traceability analysis.

[0056] Optionally, the specific steps of S6 are as follows:

[0057] S61. Receive the attack path semantic graph that has completed semantic complementation, extract the context semantic representations and corresponding intelligence embedding vectors of all attack event nodes therein, and use them for cross-vector alignment and path inference calculation preparation;

[0058] S62. Traverse all node pairs in the attack path graph, evaluate the association relationship between attack events and intelligence vectors based on semantic similarity, construct a similarity mapping matrix between nodes and intelligence, and mark the semantic hit intensity;

[0059] S63. Based on the structural information of the attack path graph, perform path propagation analysis on each node, and calculate the topological indexes of the propagation starting point potential, upstream and downstream path depths, and bifurcation influence in the entire path;

[0060] S64. Further analyze the upstream and downstream dependency strength of each node in the path, evaluate the possibility of being an attack jump key point or an abnormal propagation relay node, and form a dependency strength score vector;

[0061] S65. Combine the semantic similarity score and the path propagation and dependency scoring results, screen out the high-probability nodes with attack source characteristics, construct a candidate set of attack source nodes, and sort them based on the connectivity of the propagation path and the rationality of the upstream and downstream structures;

[0062] S66. Select the node with the best ranking in the candidate node set as the attack starting point node, generate a complete traceability path, and output the attack starting point, the node chain of the propagation path, and the auxiliary hit intelligence information.

[0063] The beneficial effects of the present invention are:

[0064] By deeply integrating the optimized Transformer network model with the black swan optimization algorithm, the present invention establishes an intelligent network threat traceability method for the actual complex attack environment. Compared with the prior art, it has significant technical advantages and application values. Traditional network threat traceability methods have many limitations in aspects such as modeling ability, path expression, intelligence fusion, and parameter self-adaptation. However, the present invention has achieved breakthrough improvements in multiple key technical links, significantly improving the accuracy, robustness, and intelligence of the traceability system.

[0065] Specifically, in the aspect of attack behavior modeling, the present invention introduces an optimized Transformer structure. By introducing a multi-scale position encoding mechanism and a stage-guided attention mask structure, the model can more accurately capture the context dependencies between attack events and the transfer features between stages, effectively solving the problem that traditional methods cannot express long-range dependencies or cross-stage attack behaviors. In the aspect of multi-modal information fusion, the present invention uniformly maps structured attack event data and unstructured threat intelligence (including IOC, TTP, attacker profiles, etc.) to a shared semantic space, constructs a cross-modal shared attention mechanism, improves the matching ability between attack nodes and intelligence items, and enables the model to still have good complementation and recognition capabilities in scenarios where information is incomplete or attack behaviors are highly concealed.

[0066] In the aspect of path reconstruction and traceability reasoning, the present invention introduces an upstream and downstream dependence strength modeling and a semantic propagation mechanism. It can reconstruct the attack path and locate potential source nodes through behavioral semantic similarity and graph structure propagation relationships in the case of incomplete attack paths or node jumps. At the same time, in terms of model parameter tuning, the present invention introduces a black swan optimization algorithm, combines behavioral mutation features and rare sample perturbation mechanisms, and dynamically optimizes key structural parameters such as modal alignment dimensions, hop diffusion factors, and stage mask control parameters, solving the problem that traditional parameter settings rely on experience and cannot adapt to multiple types of attack behaviors.

[0067] In summary, the present invention not only improves the modeling ability of multi-hop, cross-stage, and fuzzy feature attack paths, but also enhances the recognition accuracy of rare attack behaviors and the context semantic restoration ability, significantly improving the accuracy of network attack source node recognition and the overall system response efficiency. This method has strong generalization ability, high semantic expression ability, and excellent traceability performance, and has good applicability and promotion value in actual network security defense and emergency response scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention and do not constitute a limitation to the present invention. In the drawings:

[0069] Figure 1 is a flowchart of a network threat traceability method assisted by high-accuracy threat intelligence proposed by the present invention;

[0070] Figure 2 is a schematic flowchart of dynamically optimizing the hyperparameters of the Transformer network structure by the black swan optimization algorithm of a network threat traceability method assisted by high-accuracy threat intelligence proposed by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0071] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only illustrating the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.

[0072] Reference Figure 1 and Figure 2 , a network threat tracing method assisted by high-accuracy threat intelligence, comprising the following steps:

[0073] S1. Collect multi-source network security data, preprocess the multi-source network security data, and construct a time-tagged data sequence set;

[0074] S2. Construct a Transformer network model, encode the attack events in the data sequence set into a Token sequence, input it into the Transformer network model, and process the temporal information by using the position encoding and time embedding mechanism;

[0075] S3. Initialize the population parameters of the black swan optimization algorithm, and dynamically optimize the structural hyperparameters of the Transformer network model through the black swan optimization algorithm;

[0076] S4. Apply the optimized Transformer network model to the attack event sequence data, output the event-level context semantic vector, construct an attack path semantic graph, and establish the upstream and downstream attack relationship connections between nodes;

[0077] S5. Vectorize the attack features, attack indicators, and attacker tactics, techniques, and procedures (TTP) information in the threat intelligence information, embed them into the latent space output by the optimized Transformer network model, and perform joint calculations with the attack path semantic vectors to complete the semantic enhancement and complementation of the attack path nodes;

[0078] S6. According to the similarity relationship between the event vectors and the embedded intelligence vectors in the attack path semantic graph, calculate the candidate set of attack source nodes through path propagation metrics and upstream and downstream dependence strengths, generate a tracing path, and locate the attack starting point;

[0079] S7. Output the generated attack tracing path, attack starting point node information, threat intelligence features, and attack organization portrait information, and generate a structured tracing report;

[0080] S8. According to the structured tracing report, update the fitness evaluation mechanism of the individuals in the population of the black swan optimization algorithm, and re-optimize the parameters of the Transformer network model to construct a dynamic adaptive iterative optimization mechanism.

[0081] In this embodiment, the multi-source network security data specifically includes network communication logs, host behavior logs, and threat intelligence data, which are used to support the modeling of attack event sequences and the semantic analysis of attack paths.

[0082] In this embodiment, the preprocessing of the multi-source network security data specifically includes format standardization, time alignment, and noise elimination, which are used to construct an input sequence of attack events with consistent time series for the Transformer network model to learn.

[0083] In this embodiment, S2 specifically includes:

[0084] S21. Represent the constructed time-tagged data sequence set as an input sequence set where each item X t represents the t-th attack event feature vector;

[0085] S22. For each event input X t , generate a multi-scale attack context-aware position encoding vector where, is a dynamic encoding vector based on the event time difference, is an attack phase label embedding vector, is the hop count embedding vector between the event and the nearest threat intelligence hit event, and the three are used to jointly express the attack context position information;

[0086] S23. Define the embedding representation of each event as E t = X t + P t , and form the input sequence after position enhancement

[0087] S24. Construct a Transformer network model as the attack event modeling structure, and the Transformer network model is controlled by the following three innovative structural hyperparameters:

[0088] d align : The cross-modal shared attention alignment dimension, which is used to control the interaction representation dimension between the behavior modality and the intelligence modality;

[0089] r jump : The hop count attention diffusion coefficient, which is used to adjust the contribution ratio of nodes with different hop counts in the path attention calculation;

[0090] s mask : The stage-guided attention mask strategy switch parameter, which is used to enable or disable the attack stage-guided attention constraint mechanism;

[0091] S25. Input the input sequence after position enhancement into the Transformer model. Each layer performs multi-head self-attention mechanism, residual connection, and feed-forward network operations, and outputs a sequence of context semantic feature vectors for use in attack path modeling.

[0092] In this embodiment, step S3 specifically includes:

[0093] S31. Construct a population set of the black swan optimization algorithm Each individual represents three structural innovation parameters to be optimized in the Transformer network structure, where d align is the cross-modal shared attention alignment dimension, r jump is the hop number attention diffusion coefficient, and s mask is the stage-guided attention mask policy switch parameter;

[0094] S32. Define the search boundary of the individual parameters as:

[0095]

[0096] Among them, when is satisfied, the stage label multi-head hierarchical mask mechanism is enabled. The enabling of the stage label multi-head hierarchical mask mechanism specifically means that in the multi-head self-attention module of the Transformer network model, a mask matrix constructed based on the attack stage label is introduced for each attention head, so that each attention head only calculates the attention weight within a specific attack stage or between related stages, realizing the hierarchical attention and modeling of different heads for the features of different attack stages, and improving the semantic expression ability and path association accuracy of the Transformer network model for multi-stage attack chains;

[0097] S33. Introduce the behavior memory-guided perturbation mechanism and rare behavior reinforcement selection mechanism in the black swan optimization algorithm, and perform jump perturbation on the current individual x i to generate a candidate individual satisfying:

[0098]

[0099] where λ i is the jump perturbation amplitude factor, ξ i is the uniform random perturbation, ρ i is the rare behavior response coefficient, and M i is the historical winning memory perturbation vector constructed based on the feedback of rare attack samples;

[0100] S34. The candidate individual Applied to the Transformer model structure, training on the attack behavior sequence, and calculating the fitness function

[0101]

[0102] Among them, Acc rare represents the classification accuracy of the Transformer model for low-frequency attack events, F1 overall represents the overall F1 score, Div path represents the deviation penalty term generated by the attack path, and α, β, θ are control coefficients;

[0103] S35. Select the optimal individual in the next-generation population using the rare sample priority strategy. If the optimal individual has stable performance in multiple rare behavior distribution regions, increase the perturbation replication weight;

[0104] S36. Determine whether the termination condition is met. If it is met, output the optimal individual; otherwise, return to S33 to continue the optimization iteration process.

[0105] In this embodiment, the specific steps of S4 are as follows:

[0106] S41. Based on the optimized Transformer network model, perform inference on the attack event sequence to obtain the context semantic representation vector of each event node. At the same time, extract the corresponding context state labels of the nodes, including the attack stage identifier, semantic mutation degree, and model confidence, for constructing the multi-dimensional semantic label set of the graph nodes;

[0107] S42. According to the dynamic matching result of the similarity between the order of event nodes on the time axis and the semantic representation, construct the basic connection edge set, and complete the structure according to the behavior labels of the nodes and the transition relationship between upstream and downstream stages to form the initial attack behavior graph structure;

[0108] S43. Introduce a dynamic weight decay function for all edges in the graph, comprehensively calculate the edge weights based on the hop count, intelligence similarity, and stage inconsistency, and generate an adjustable upstream and downstream propagation probability matrix for controlling the path credibility mapping strategy;

[0109] S44. Introduce a rare behavior detection module to mark the events with low model recognition confidence and significantly deviated behavior characteristics among the event nodes, and establish a "rare behavior key node marking layer", which is used as an overlay sub-structure for path priority analysis in the graph;

[0110] S45. Introduce a cross-modal edge enhancement mechanism to establish semantic auxiliary connections between the structured attack event nodes and the hit nodes in the unstructured threat intelligence vector, form an intelligence-driven auxiliary edge set, and reinforce the information jump hole area in the path;

[0111] S46. After completing the optimization of the graph structure, perform structural normalization on the attack path graph, including redundant edge pruning, graph structure sparsification, and semantic role classification reconstruction, and finally output an attack path semantic graph with stage awareness, path stability, and semantic consistency.

[0112] In this embodiment, the specific steps of S5 are as follows:

[0113] S51. Extract threat intelligence data related to attack behaviors, including attack feature fields, attack indicator entries, attack organization identifiers, and corresponding tactics, techniques, and procedures information, and perform structural cleaning and semantic standardization processing on the threat intelligence data.

[0114] S52. Perform multi-channel embedding processing on the preprocessed threat intelligence data, encode structured fields, TTP tags, and unstructured text respectively, and generate a unified format set of intelligence vectors as a cross-modal semantic information source.

[0115] S53. Embed the intelligence vectors into the hidden space dimension corresponding to the output of the optimized Transformer network model, construct an aligned intelligence vector set that matches the context semantic representation of the attack path nodes, and introduce stage labels and confidence factors for intelligence screening.

[0116] S54. Perform joint attention calculation on the semantic vectors of the attack path nodes output by the optimized Transformer network model and the aligned intelligence vectors, establish a semantic similarity mapping relationship, and determine the high-correlation pairing between nodes and intelligence.

[0117] S55. For attack nodes that do not directly hit intelligence entries, infer and supplement missing behavior labels, attack stages, or TTP information based on the high semantic similarity relationship between intelligence vectors and context features, and achieve semantic enhancement and context completion of node attributes.

[0118] S56. Write the completed node semantic attributes into the attack path semantic graph, update the semantic descriptions and classification labels of each node in the graph, complete the enhancement of the graph structure at the semantic level and the improvement of the path content, and improve the accuracy and integrity of the traceability analysis.

[0119] In this embodiment, the specific steps of S6 are as follows:

[0120] S61. Receive the attack path semantic graph that has completed semantic completion, extract the context semantic representations of all attack event nodes and the corresponding intelligence embedding vectors therein for preparing cross-vector alignment and path inference calculation.

[0121] S62. Traverse all node pairs in the attack path graph, evaluate the correlation between attack events and intelligence vectors based on semantic similarity, construct a similarity mapping matrix between nodes and intelligence, and mark the semantic hit intensity.

[0122] S63. Based on the structural information of the attack path graph, perform path propagation analysis on each node, and calculate topological metrics such as the propagation start potential, upstream and downstream path depths, and bifurcation influence in the entire path.

[0123] S64. Further analyze the upstream and downstream dependency strength of each node in the path, evaluate the possibility of being a key point for attack jump or an abnormal propagation relay node, and form a dependency strength score vector.

[0124] S65. Combine the semantic similarity scores with the path propagation and dependency scoring results, screen out high-probability nodes with attack source characteristics, construct a candidate set of attack source nodes, and sort them based on the connectivity of the propagation path and the rationality of the upstream and downstream structures.

[0125] S66. Select the node with the best ranking in the candidate node set as the attack starting node, generate a complete traceability path, and output the attack starting point, the chain of propagation path nodes, and the auxiliary hit intelligence information.

[0126] Example 1:

[0127] To verify the feasibility of the present invention in implementation, the present invention is applied to the internal network environment of the data center of a large financial institution. The security team has long faced a large number of distributed threat behaviors and penetration attempts of advanced persistent threats (APTs). Especially in regular actual combat defense and offense drills and red team tests, the attack methods show significant characteristics such as multi-hop, cross-stage, and high concealment. In the past, the unit used a traditional traceability platform based on rule matching and log analysis for path recovery and attacker identification. Although it could cover some obvious intrusion traces, the accuracy was not high and the response was lagged in complex scenarios, and it could not meet the precise positioning and closed-loop defense requirements in the current threat environment.

[0128] In March 2025, the unit introduced the network threat traceability system assisted by high-accuracy threat intelligence proposed by the present invention, and conducted a two-week real-data test and verification on the internal deployment environment. In this test, the system performed traceability modeling on four different APT attack simulation scenarios (numbered APT-Case-A to APT-Case-D). In each scenario, there were approximately 1,400 to 1,900 attack event nodes, the attack chain was complex, the path was multi-hop, and there were behaviors such as zero-day exploitation, lateral movement, and privilege maintenance mixed.

[0129] In practical applications, the method of the present invention first performs temporal modeling on attack events through an optimized Transformer model, and uses multi-scale positional encoding and phase-aware attention mechanism to enhance the model's ability to express the transitional behavior of attack phases. Then, combined with the black swan optimization algorithm, key parameters such as the alignment dimension, hop diffusion, and phase mask of the Transformer structure are adaptively adjusted to ensure that the model can still maintain high robustness when facing rare attack samples or sudden behaviors.

[0130] Immediately afterwards, the system vectorizes and embeds the IOC, TTP, and attack organization data from the external intelligence platform into the model's latent space, and fuses and complements them with the semantic representations of each attack node. For the nodes that do not match the intelligence items, label backtracking is performed through context semantic alignment, effectively solving the problem of missing behavior labels in the path graph. Finally, based on the attack path graph structure and node propagation weights, the system completes the candidate screening of the source node, the positioning of the attack starting point, and the output of the complete path chain.

[0131] Through comparative analysis with traditional methods, the results show that the path restoration accuracy of the present invention in four test scenarios reaches 89.5%, 91.3%, 92.4%, and 90.1% respectively, which is an average increase of more than 13 percentage points compared with traditional methods. In terms of the recognition accuracy of the attack source node, the present invention achieves a recognition effect of 92.3% to 94.8%, while the traditional method stays between 74% and 77%, with a significant improvement. At the same time, the semantic graph construction task is completed within an average of 19 seconds, and nearly 300 to 400 node semantic information is successfully complemented through intelligence-driven, and the node complementation rate reaches more than 85%, significantly enhancing the integrity and interpretability of the path.

[0132] Table 1 Comparison table of the traceability effects of traditional methods and the present invention in APT attack scenarios

[0133]

[0134] According to the data in Table 1, in four representative APT attack simulation scenarios (APT-Case-A to APT-Case-D), the performance of the traditional traceability method and the intelligent traceability method based on the optimized Transformer network and black swan algorithm proposed by the present invention was evaluated respectively. First, from the perspective of the event scale, the total number of attack events in each test scenario is between 1380 and 1872, all of which are medium and large-scale attack chain behavior sequences under real simulation, ensuring the wide applicability and scenario coverage of the test.

[0135] In terms of "path restoration accuracy", the accuracy rates of traditional methods in the four scenarios are 76.2%, 78.4%, 79.1% and 77.5% respectively, all of which do not exceed 80%, reflecting the lack of their ability to model behavior dependencies and paths in complex, multi-hop attack chain scenarios. The method of the present invention achieved path restoration accuracy rates of 89.5%, 91.3%, 92.4% and 90.1% in the same scenarios. Not only did all of them exceed the 90% mark, but they also improved by 13.3%, 12.9%, 13.3% and 12.6% respectively compared with the traditional methods, realizing a stable and significant performance leap. This shows that introducing the Transformer deep modeling and intelligence semantic fusion mechanism effectively improves the logical consistency of path construction and the integrity of the behavior chain.

[0136] In terms of the "attack source identification accuracy" indicator, traditional methods generally fall in the medium to low level of 74% to 77%. In multi-stage attack chains, misjudgments in tracing often occur due to source point camouflage or behavior jumps. The method of the present invention is significantly superior to traditional methods, achieving accuracy rates of 92.3%, 93.7%, 94.8% and 93.1% respectively in the four scenarios, with an overall improvement of more than 17 percentage points. This performance advantage benefits from the upstream and downstream dependence strength analysis mechanism and path propagation evaluation strategy designed in the present invention. Combined with the node semantic association relationship established after intelligence embedding, the model has higher accuracy and stability in source node reasoning.

[0137] From the perspective of efficiency, in the "average path construction duration" indicator, the present invention took 18.5 seconds, 20.2 seconds, 17.9 seconds and 19.1 seconds respectively in the four scenarios, on average about 5 seconds lower than the traditional reconstruction mechanism, showing that its semantic mapping and parallel attention calculation mechanism have good execution efficiency while maintaining accuracy, fully meeting the requirements of actual tracing scenarios for timeliness.

[0138] In terms of multi-modal fusion ability, the present invention embeds IOC and TTP intelligence into the Transformer semantic space, and the number of node semantic labels supplemented in each scenario reaches 294, 351, 406 and 389 respectively. The corresponding "average node completion rate" is 83.7%, 86.1%, 88.2% and 85.4% respectively, effectively solving the problems of missing path node feature information and unclear semantic expression, and providing key support for the logical restoration of the attack chain and the judgment of attack stages. Due to the lack of an intelligence cross mechanism, traditional methods basically cannot achieve such processing in terms of completion ability.

[0139] In summary, the present invention not only comprehensively surpasses the traditional methods in terms of key performance indicators (accuracy, path restoration, recognition rate), but also performs excellently in terms of model response time and node information integrity, demonstrating a high degree of intelligence, engineering usability, and promotion value. It is particularly suitable for security traceability and threat tracking tasks in multi-stage and highly concealed attack environments.

[0140] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and all should be covered within the protection scope of the present invention.

Claims

1. A network threat tracing method assisted by high-accuracy threat intelligence, characterized in that, It includes the following steps: S1. Collect multi-source network security data, preprocess the multi-source network security data, and construct a time-tagged data sequence set; S2. Construct a Transformer network model, encode the attack events in the data sequence set into a Token sequence, input it into the Transformer network model, and process the temporal information using the positional encoding and time embedding mechanism; S3. Initialize the population parameters of the black swan optimization algorithm, and dynamically optimize the structural hyperparameters of the Transformer network model through the black swan optimization algorithm; S4. Apply the optimized Transformer network model to the attack event sequence data, output the event-level context semantic vector, construct an attack path semantic graph, and establish the upstream and downstream attack relationship connections between nodes; S5. Vectorize the attack features, attack indicators, and attacker tactics, techniques, and procedures (TTP) information in the threat intelligence information, embed them into the latent space output by the optimized Transformer network model, and perform joint calculations with the attack path semantic vectors to complete the semantic enhancement and complementation of the attack path nodes; S6. According to the similarity relationship between the event vectors and the embedded intelligence vectors in the attack path semantic graph, calculate the candidate set of attack source nodes through path propagation metrics and upstream and downstream dependence strengths, generate a tracing path, and locate the attack starting point; S7. Output the generated attack tracing path, attack starting point node information, threat intelligence features, and attack organization portrait information, and generate a structured tracing report; S8. According to the structured tracing report, update the fitness evaluation mechanism of the individuals in the black swan optimization algorithm population, and re-optimize the parameters of the Transformer network model to construct a dynamic adaptive iterative optimization mechanism.

2. A network threat tracing method assisted by high-accuracy threat intelligence according to claim 1, characterized in that, The multi-source network security data specifically includes network communication logs, host behavior logs, and threat intelligence data, which are used to support the modeling of attack event sequences and the semantic analysis of attack paths.

3. A method for tracing network threats assisted by high-accuracy threat intelligence according to claim 1, characterized in that, The preprocessing of the multi-source network security data specifically includes format standardization, time alignment, and noise elimination, which are used to construct an attack event input sequence with consistent time series and suitable for learning by the Transformer network model.

4. A network threat tracing method assisted by high-accuracy threat intelligence according to claim 1, characterized in that, The specific content of S2 includes: S21. Represent the constructed time-marked data sequence set as a set of input sequences where each item X t represents the feature vector of the t-th attack event; S22. For each event input X t , generate a multi-scale attack context-aware position encoding vector Among them, is a dynamic encoding vector based on the event time difference, is an attack phase label embedding vector, is the hop count embedding vector between the event and the event with the most recent threat intelligence hit. The three are used to jointly express the attack context position information; S23. Define the embedded representation of each event as E t = X t + P t , to form the input sequence after position enhancement S24. Construct a Transformer network model as the attack event modeling structure, and the Transformer network model is controlled by the following three innovative structural hyperparameters: d align : Cross-modal shared attention alignment dimension, used to control the interaction representation dimension between the behavior modality and the intelligence modality; r jump : Hop count attention diffusion coefficient, which is used to adjust the contribution ratio of nodes with different hop counts in path attention calculation; s mask : Phase-guided attention mask strategy switch parameter, used to enable or disable the attention constraint mechanism guided by the attack phase; S25. Input the position-enhanced input sequence into the Transformer model, and perform multi-head self-attention mechanism, residual connection, and feed-forward network operations in each layer, and output a context semantic feature vector sequence for attack path modeling.

5. A method for network threat tracing assisted by high-accuracy threat intelligence according to claim 1, characterized in that, The specific content of S3 includes: S31. Construct the population set of the black swan optimization algorithm Each individual represents three structural innovation parameters to be optimized in the Transformer network structure. Among them, d align is the cross-modal shared attention alignment dimension, r jump is the hop number attention diffusion coefficient, and s mask is the phase-guided attention mask strategy switch parameter; S32. Define the search boundary of the individual parameters as: Among them, when is satisfied, the enabling phase label multi-head hierarchical masking mechanism is enabled. Specifically, in the multi-head self-attention module of the Transformer network model, a masking matrix constructed based on the attack phase label is introduced for each attention head, so that each attention head calculates the attention weights only within a specific attack phase or between relevant phases, realizing the hierarchical attention and modeling of different heads for the features of different attack phases, and improving the semantic expression ability and path association accuracy of the Transformer network model for multi-phase attack chains; S33. Introduce the behavioral memory-guided perturbation mechanism and rare behavior reinforcement selection mechanism in the black swan optimization algorithm to perform jump perturbation on the current individual x i to generate a candidate individual satisfying: Among them, λ i is the jump perturbation amplitude factor, ξ i is the uniform random perturbation, ρ i is the rare behavior response coefficient, M i is the historical winning memory perturbation vector constructed based on the feedback of rare attack samples; S34. Apply the candidate individual to the Transformer model structure to train the attack behavior sequence and calculate the fitness function Among them, Acc rare represents the classification accuracy of the Transformer model for low-frequency attack events, and F1 overall represents the overall F1 score, and Div path represents the deviation penalty term for attack path generation, where α, β, and θ are control coefficients; S35. Adopt the rare sample priority strategy to select the optimal individual in the next generation population. If the optimal individual has stable performance in multiple rare behavior distribution regions, increase the perturbation replication weight; S36. Determine whether the termination condition is satisfied. If it is satisfied, output the optimal individual; otherwise, return to S33 to continue the optimization iteration process.

6. A method for tracing network threats assisted by threat intelligence with high accuracy according to claim 1, characterized in that, The specific steps of S4 are as follows: S41: Infer the attack event sequence based on the optimized Transformer network model to obtain the context semantic representation vectors of each event node. Meanwhile, extract the corresponding context state labels of the nodes, including attack phase identifiers, semantic mutation degrees, and model confidence levels, for constructing the multi-dimensional semantic label set of the graph nodes; S42: Construct the basic connection edge set according to the dynamic matching result of the similarity between the order of event nodes on the time axis and the semantic representation, and complete the structure complement according to the behavior labels of the nodes and the upstream and downstream phase transition relationships to form the initial attack behavior graph structure; S43: Introduce a dynamic weight decay function for all edges in the graph, comprehensively calculate the edge weights based on the hop count, intelligence similarity, and phase inconsistency, and generate an adjustable upstream and downstream propagation probability matrix for controlling the path credibility graph construction strategy; S44: Introduce a rare behavior detection module to mark the events with low model recognition confidence and significantly deviating behavior characteristics among the event nodes, and establish a "rare behavior key node marking layer" as the graph overlay sub-structure for priority path analysis; S45: Introduce a cross-modal edge enhancement mechanism to establish semantic auxiliary connections between the structured attack event nodes and the hit nodes in the unstructured threat intelligence vectors, forming an intelligence-driven auxiliary edge set to strengthen the information jump void area in the path; S46: After completing the graph structure optimization, perform structure normalization processing on the attack path graph, including redundant edge trimming, graph structure sparsification, and semantic role classification reconstruction, and finally output the attack path semantic graph with phase awareness, path stability, and semantic consistency.

7. A method for tracing network threats assisted by threat intelligence with high accuracy according to claim 1, characterized in that, The specific steps of S5 are as follows: S51: Extract the threat intelligence data related to the attack behavior, including attack feature fields, attack indicator entries, attack organization identifiers, and corresponding tactics, techniques, and procedures information, and perform structure cleaning and semantic standardization processing on the threat intelligence data; S52: Perform multi-channel embedding processing on the preprocessed threat intelligence data, encode the structured fields, TTP tags, and unstructured texts respectively to generate a unified format of intelligence vector set as the cross-modal semantic information source; S53: Embed the intelligence vectors into the hidden space dimension corresponding to the output of the optimized Transformer network model, construct an aligned intelligence vector set matching the context semantic representation of the attack path nodes, and introduce phase labels and confidence factors for intelligence screening; S54: Perform joint attention calculation on the semantic vectors of the attack path nodes output by the optimized Transformer network model and the aligned intelligence vectors, establish a semantic similarity mapping relationship, and determine the high-correlation pairing between the nodes and the intelligence; S55: For the attack nodes that do not directly hit the intelligence entries, infer and supplement the missing behavior labels, attack phases, or TTP information based on the high semantic similarity relationship between the intelligence vectors and the context features to achieve semantic enhancement and context complement of the node attributes. S56. Write the completed node semantic attributes into the attack path semantic graph, update the semantic descriptions and classification labels of each node in the graph, complete the enhancement of the graph structure at the semantic level and the improvement of the path content, and improve the accuracy and integrity of the traceability analysis.

8. A method for tracing network threats assisted by threat intelligence with high accuracy as claimed in claim 1, wherein, The specific steps of S6 are as follows: S61. Receive the attack path semantic graph that has completed semantic completion, extract the context semantic representations and corresponding intelligence embedding vectors of all attack event nodes therein, for performing cross-vector alignment and path inference calculation preparation; S62. Traverse all node pairs in the attack path graph, evaluate the correlation between attack events and intelligence vectors based on semantic similarity, construct a similarity mapping matrix between nodes and intelligence, and mark the semantic hit intensity; S63. Based on the structural information of the attack path graph, perform path propagation analysis on each node, and calculate the topological indexes of the propagation starting point potential, upstream and downstream path depths, and bifurcation influence in the entire path; S64. Further analyze the upstream and downstream dependence strength of each node in the path, evaluate the possibility of being an attack jump key point or an abnormal propagation relay node, and form a dependence strength score vector; S65. Combine the semantic similarity scores and the path propagation and dependence scoring results, screen out the high-probability nodes with attack source characteristics, construct a candidate set of attack source nodes, and sort them based on the propagation path connectivity and the rationality of the upstream and downstream structures; S66. Select the node with the best ranking in the candidate node set as the attack starting point node, generate a complete traceability path, and output the attack starting point, the propagation path node chain, and the auxiliary hit intelligence information.

Citation Information

Cited By

  • Multi-level power network threat collaborative identification method and system

    CN120658530A

  • Quantitative analysis method and device for robustness of false threat intelligence recognition model

    CN120811725A

  • A false threat intelligence identification model robustness quantitative analysis method and device

    CN120811725B

  • Network security data analysis system and method based on artificial intelligence

    CN120856418A

  • Information transmission system and transmission method based on semantic model

    CN121000652A