Method and system for constructing network threat knowledge graph based on air traffic control system

The method constructs an air traffic management system network threat knowledge graph using threat intelligence and adversarial data, addressing the lack of red-blue adversarial consideration in existing methods, enhancing threat analysis and visualization for improved security.

CN120321029APending Publication Date: 2025-07-15刘超
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510747643.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-07-15

Smart Images

  • Figure CN120321029A_ABST
    Figure CN120321029A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of knowledge graph construction, in particular to a network threat knowledge graph construction method and system based on an air traffic control system, and the method comprises the steps: obtaining various data of the air traffic control system in the presence of network threats; determining a plurality of entities in the air traffic control system network threat and a relationship among the entities; and constructing the knowledge graph ATMCyKG according to the data in all entities and the relationship among the entities. According to the method, by constructing the knowledge graph ATMCyKG, security experts can be helped to better understand and sort network threat information in the air traffic control system, the attack and defense process in a real scene of the air traffic control system is analyzed, and effective reference is provided for improving the security of the air traffic control system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of knowledge graph construction, and in particular, to a method and system for constructing an air traffic control system network threat knowledge graph. Background Art

[0002] While the air traffic control system is increasingly developing digitally and networked, it also faces increasingly complex network threats. These threats include, but are not limited to, cyberattacks, malware, data breaches, identity theft, insider threats, supply chain attacks, communication jamming, etc. These threats not only threaten the security of the air traffic control system, but also pose a great risk to the safety of flights, the lives of pilots and passengers. Therefore, the air traffic control system must strengthen network security protection, continuous monitoring, and timely update of security measures to cope with various potential network threats.

[0003] In the existing knowledge graph construction technologies, the knowledge graphs are usually constructed based on architectures and processes, without considering the red-blue confrontation in network security. In the construction of knowledge graphs considering red-blue confrontation, it is based on how attackers conduct attacks through these technologies and means, and how the blue team defends and counterattacks through corresponding technologies; the original technologies and red-blue confrontation have different focuses in the process of constructing knowledge graphs. Summary of the Invention

[0004] The present invention provides a method and system for constructing an air traffic control system network threat knowledge graph, which is used to solve the problem of lack of full consideration of red-blue confrontation in network security in the existing knowledge graph construction technologies.

[0005] The object of the present invention can be achieved by the following technical solutions:

[0006] The first aspect of the present invention is to provide a method for constructing an air traffic control system network threat knowledge graph, including:

[0007] Obtain various data of the air traffic control system under network threats;

[0008] According to the various data of the air traffic control system, obtain several entities under the network threats of the air traffic control system and the relationships between the entities;

[0009] Construct a knowledge graph ATMCyKG through several entities and the relationships between the entities.

[0010] Further, the various data of the air traffic control system under network threats include: threat intelligence, attack simulation, red-blue confrontation drill data, and log analysis data.

[0011] Further, the obtaining of several entities under the network threats of the air traffic control system and the relationships between the entities according to the various data of the air traffic control system includes:

[0012] The network model is trained by the TCFLTransformer method with a CNN-Transformer hybrid architecture based on the UNSW-NB15 dataset to obtain the trained TCFLTransformer. With the trained TCFLTransformer, various data of the air traffic control system under network threats are used as inputs, and several entities under the network threats of the air traffic control system are output.

[0013] The relationships between the entities are determined through the relevance between the red and blue confrontations.

[0014] Further, the several entities include:

[0015] Air traffic control system host asset dimension AHA, asset system business type dimension AC, asset network division domain dimension AND, asset vulnerability dimension AV, attack strategy dimension ATa, attack technology dimension ATe, attack software and process dimension AP, attack impact dimension AI, attacker dimension TA, attack motivation dimension AM, actor ability dimension AA, and air traffic control system security guardian dimension ASG.

[0016] Further, the relationships between the entities include:

[0017] AHA belongs to AC, AHA is located in AND, AHA exists in AV, ATe exploits AV, ATe threatens AHA, ATe obtains ATa, ATe executes AI, AV is located in AND, AV belongs to AC, AP completes ATe, AP obtains ATa, AP executes AI, TA owns AP, TA is used for AA, TA discovers AM, TA exploits AV, TA is used for ATe, TA completes AI, ASG protects AHA, ASG repairs AV, ASG confronts ATe, ASG blocks Ata, AA depends on AV, AND belongs to AC.

[0018] Further, constructing the knowledge graph ATMCyKG through the several entities and the relationships between the entities includes:

[0019] The knowledge graph ATMCyKG is constructed using the graph database software Neo4j according to the several entities and the relationships between the entities.

[0020] Further, the specific process of constructing the knowledge graph ATMCyKG using the graph database software Neo4j is as follows:

[0021] The first step: Environment configuration and preparation of CSV files;

[0022] The second step: Execute the import command;

[0023] Step 3: Import of node data;

[0024] Step 4: Import of relationship data;

[0025] Step 5: Verify the execution result of the knowledge graph ATMCyKG.

[0026] The second aspect of the present invention is to provide a construction system based on an air traffic control system network threat knowledge graph, including:

[0027] A data acquisition module, configured to obtain various data of the air traffic control system under network threats;

[0028] An entity analysis module, configured to obtain several entities under the network threat of the air traffic control system and the relationships between the entities according to various data of the air traffic control system;

[0029] A knowledge graph construction module, configured to construct the knowledge graph ATMCyKG through several entities and the relationships between the entities.

[0030] The third aspect of the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, where when the processor executes the computer program, it implements the construction method of the air traffic control system network threat knowledge graph.

[0031] The fourth aspect of the present invention is to provide a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the construction method of the air traffic control system network threat knowledge graph.

[0032] Compared with the prior art, the beneficial effects of the present invention are: The knowledge graph ATMCyKG is constructed through the data in all entities and the relationships between the entities. The constructed knowledge graph ATMCyKG can help security experts better understand and sort out the network threat information in the air traffic control system, analyze the attack and defense processes in the real scenarios of the air traffic control system, provide an effective reference for improving the security of the air traffic control system, and present the complex air traffic control system network threat information to users in an intuitive and easy-to-understand manner, and can clearly and intuitively display the security situation of the air traffic control system network threat, and has broad application prospects in the industry field. Description of the Drawings

[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0034] Figure 1 The present invention provides a step flowchart of a construction method for a network threat knowledge graph based on an air traffic control system;

[0035] Figure 2 The present invention provides a module flowchart of a construction system for a network threat knowledge graph based on an air traffic control system. Specific embodiments

[0036] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.

[0037] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0038] In view of the problems in the background technology, researching and designing a construction method and system for a network threat knowledge graph based on an air traffic control system has important practical significance.

[0039] As Figure 1 shown, the first aspect of the present invention is to provide a construction method for a network threat knowledge graph based on an air traffic control system, including:

[0040] Step S001: Collect various data of the air traffic control system under network threats.

[0041] It should be noted that in the process of constructing a knowledge graph of conventional technologies, the data sources are mostly technical documents, standards and specifications, development practices, industry reports, etc., focusing on the standardized and conventional knowledge in the technical field. These data sources are more stable and have a slower update speed, and are usually used for long-term stable architecture design. In the process of constructing a knowledge graph for red-blue confrontation based on cyber threats, the data sources include threat intelligence, attack simulation, red-blue confrontation drill data, log analysis data, etc. These data collect attack events, vulnerability reports, security detection results, etc., and further construct the attack and defense paths in the graph. The goal is to continuously iterate and update the graph to cope with new attack methods.

[0042] Specifically, collect various data of the air traffic control system under cyber threats; among them, the various data include: threat intelligence, attack simulation, red-blue confrontation drill data, log analysis data, etc. Among them, the various data can be obtained from the basic databases in the field of network security, reports of international aviation authorities, and scientific literature of global research institutions.

[0043] Thus, various data of the air traffic control system under cyber threats are obtained.

[0044] Step S002: According to the various data of the air traffic control system, obtain several entities under the cyber threats of the air traffic control system and the relationships between the entities.

[0045] It should be noted that for the red-blue confrontation based on cyber threats, this kind of knowledge graph focuses on describing elements related to network security, especially the confrontation between the attacker (red team) and the defender (blue team). The goal is to simulate, detect, and prevent cyber attacks and improve the security of the system through confrontation drills. Therefore, the nodes and edges in the knowledge graph mainly revolve around attack means, vulnerabilities, vulnerability exploitation, threat models, defense strategies, emergency responses, etc. In the air traffic control system, the knowledge graph focuses on how to identify and defend against cyber attacks, intrusion detection, abnormal behavior monitoring, etc., to ensure that the air traffic control system can effectively respond to various cyber attacks; therefore, several entities are selected according to the focus to construct the knowledge graph.

[0046] Specifically, according to the UNSW-NB15 dataset (University of New South Wales Network-Based Intrusion Detection System 2015), the TCFLTransformer (TextCNN-Flat-LatticeTransformer) method of the CNN-Transformer hybrid architecture is used to train the network model, obtaining the trained TCFLTransformer. Through the trained TCFLTransformer, various data of the air traffic control system under network threats are used as inputs, and several entities under the network threats of the air traffic control system are output. The relationships between the entities are determined through the relevance between the red and blue confrontations.

[0047] Among them, the entities include: the air traffic control system host asset dimension AHA, the asset system business type dimension AC, the asset network division domain dimension AND, the asset vulnerability dimension AV, the attack strategy dimension ATa, the attack technology dimension ATe, the attack software and process dimension AP, the attack impact dimension AI, the attacker dimension TA, the attack motivation dimension AM, the actor ability dimension AA, and the air traffic control system security guardian dimension ASG. Among them, the TCFLTransformer method of the CNN-Transformer hybrid architecture is a publicly available technical method.

[0048] Among them, the information contained in each entity is as follows;

[0049] The air traffic control system host asset dimension (AHA, Air Traffic Management Asset Host Architecture). The air traffic control system host asset dimension includes the main systems and modules that should be protected in the air traffic management system, mainly involving various devices, subsystems, and components of the air traffic control system, including various devices, systems, and service components in the aircraft system.

[0050] Asset System Business Type Dimension (AC, Asset Categorization). The asset system business type dimension refers to the subsystems divided by the air traffic control system according to its functions and roles, including Communication Systems (CS), Surveillance & Information Systems (SIS), Emergency Avoidance Systems (EAS), Navigation Systems (NS), Entertainment & Auxiliary Systems (EAS), and External Connectivity (EC).

[0051] Asset Network Division Domain Dimension (AND, Asset Network Domain). According to the ARINC 664P5 (Aeronautical Radio, Incorporated 664 Part 5) and ARINC 811 (Aeronautical Radio, Incorporated 811) standards, the user and service data of avionics systems are classified into avionics network domains with different security levels. ACD (Aircraft Control Display) is mainly for flight crew and mainly involves the safe flight functions of the aircraft, with very high requirements for the security and reliability of the system. AISD (Aircraft Information and Systems Display) is mainly for airlines and maintenance personnel and includes services related to flight support, passenger services, aircraft maintenance information management, etc. These services related to aircraft operation and maintenance functions have certain security level requirements. PIESD (Passenger Information and Entertainment System Display) is mainly for passengers using in-flight entertainment equipment, providing diverse information and services to passengers, with relatively low security level requirements. Among them, ARINC 664P5 and ARINC 811 are standards related to avionics systems.

[0052] Asset Vulnerabilities Dimension (AV). The asset vulnerabilities dimension refers to the vulnerability information existing in the host assets of the air traffic control system. Assets or technologies have characteristics that make them vulnerable to attacks. For example, ADS-B (Automatic Dependent Surveillance-Broadcast) lacks basic security mechanisms such as authentication, message integrity check, and encryption, which poses a risk of cyber attacks when applying this protocol in crowded airspace. The Second Surveillance Radar (SSR) system is vulnerable to attacks such as spoofing, jamming, and overloaded interrogation, and overloaded interrogation will affect the availability of the SSR system. Controller Pilot Data Link Communications (CPDLC) is not encrypted, so attackers are allowed to access and control messages, modify their content, and send false messages to ground stations and aircraft.

[0053] Attack Tactics Dimension (Ata). The attack tactics dimension refers to the specific strategies adopted by attackers when implementing cyber attacks. Attack strategies aim to achieve the malicious purposes of attackers, mainly referring to the tactical goals and the intentions of executing actions during the attack. Attack tactics include reconnaissance, initial access, persistence, discovery, lateral movement, command and control, evasion, weakening support communication, and impact.

[0054] Attack Technology Dimension (ATe). The attack technology dimension mainly records information on the attack technologies for various vulnerabilities in the vulnerability dimension. Attack technologies include attack sub-technologies. The attack means adopted by attackers may include a series of sub-technologies. For example, the Public Sky Scanners attack technology includes sub-technologies such as radio receiver reception, parsing, and message aggregation.

[0055] Attack Software and Procedures Dimension (AP). The attack software and procedures dimension refers to the specific details of how attackers execute programs to achieve technologies. There are many types included, and there are different attack software and procedures for implementing the same attack technology.

[0056] Attack Impact Dimension (AI). The attack impact dimension refers to the impact on the air traffic control system or aircraft after a cyber attack. The attack impacts include aircraft being tracked, Dos (Diversion of Service) - passengers, Dos - crew members, Dos - pilots, loss of aircraft control, loss of security, loss of availability, visual manipulation, control manipulation, isolation from the monitoring system, theft of passenger information, etc.

[0057] Threat Actors Dimension (TA). The threat actors dimension mainly refers to individuals, groups or countries that affect or may affect the security of the air traffic control system or the security of the aircraft. According to the motivation of the attacker, the attack capabilities possessed and the damage caused, they are classified into six levels in sequence, including criminal opportunists, cyber hackers and non - organized criminal groups, intelligence agencies, etc.

[0058] Attack Motivation Dimension (AM). The attack motivation dimension refers to the potential intention or reason that drives an individual or group to carry out malicious activities. The motivations for the attack include implanting advertisements, for reputation, economic interests, spreading fear, releasing threat signals, etc.

[0059] Actor Ability Dimension (AA). The attacker ability refers to the capabilities that an attacker needs to possess to launch an attack. Threat participants have different confrontation capabilities, so they may execute different attack techniques. The capabilities of the attacker include radio frequency broadcast signal, positioning ability, device intervention ability, prior knowledge ability, wireless communication ability, satellite control ability, etc.

[0060] Avionics Security Guardian Dimension (ASG). The avionics security guardianship refers to individuals, teams or organizations that, as the guardians of the air traffic control system network security, resist against intruders and shoulder the heavy responsibility of the air traffic control system network security.

[0061] Determine the relationships between all entity - corresponding dimensions through the relevance between red - blue confrontation.

[0062] There are the following 24 relationships between all dimensions, as shown in Table 1.

[0063] Table 1 Relationships between Dimensions

[0064]

[0065]

[0066] Step S003: Construct the knowledge graph ATMCyKG through several entities and the relationships between entities.

[0067] According to the entities under the network threats of the air traffic control system, the attribute data in the entity data, and the relationships between entities, the knowledge graph ATMCyKG (ATM Cyber Knowledge Graph) is constructed through the graph database software Neo4j.

[0068] Among them, the specific process of constructing the knowledge graph ATMCyKG using the graph database software Neo4j is as follows:

[0069] The first step is environmental configuration and preparation of CSV files, including configuring the java environment jdk and jre, and then decompressing.

[0070] The second step is to execute the import command.

[0071] The third step is to import node data.

[0072] The fourth step is to import relationship data.

[0073] The fifth step is to verify the execution result of the knowledge graph ATMCyKG.

[0074] As Figure 2 shown, the second aspect of the present invention is to provide a construction system based on the knowledge graph of air traffic control system network threats, including:

[0075] A data acquisition module 101, which is used to obtain various data of the air traffic control system under network threats.

[0076] An entity analysis module 102, which is used to obtain several entities under the network threats of the air traffic control system and the relationships between entities according to various data of the air traffic control system.

[0077] A knowledge graph construction module 103, which is used to construct the knowledge graph ATMCyKG through several entities and the relationships between entities.

[0078] The third aspect of the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, a construction method based on the knowledge graph of air traffic control system network threats is implemented.

[0079] The fourth aspect of the present invention is to provide a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, a construction method based on the knowledge graph of air traffic control system network threats is implemented.

[0080] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) that contain computer-usable program code.

[0081] The present invention is described with reference to the flowcharts and / or block diagrams of methods, systems, and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0082] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0083] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, such that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that it is still possible to modify the specific implementation manners of the present invention or make equivalent substitutions. Any modification or equivalent substitution that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the present invention.

Claims

1. A construction method of a knowledge graph based on network threat of an air traffic control system, characterized in that Including: Obtain various data of the air traffic management (ATM) system under network threats; Based on the various data of the ATM system, obtain several entities under network threats to the ATM system and the relationships between the entities; Construct a knowledge graph ATMCyKG through several entities and the relationships between the entities.

2. The construction method of a knowledge graph based on network threat of an air traffic control system according to claim 1, wherein The various data of the ATM system under network threats include: threat intelligence, attack simulation, red-blue confrontation drill data, and log analysis data.

3. The construction method of a knowledge graph based on network threat of an air traffic control system according to claim 1, characterized in that, The obtaining of several entities under network threats to the ATM system and the relationships between the entities based on the various data of the ATM system includes: Train a network model by the TCFLTransformer method of the CNN-Transformer hybrid architecture based on the UNSW-NB15 dataset to obtain the trained TCFLTransformer. Using the trained TCFLTransformer, take the various data of the ATM system under network threats as input and output several entities under network threats to the ATM system; Determine the relationships between the entities through the relevance between red-blue confrontations.

4. A construction method of a knowledge graph based on air traffic control system network threat, according to claim 3, characterized in that The several entities include: ATM system host asset dimension AHA, asset system business type dimension AC, asset network division domain dimension AND, asset vulnerability dimension AV, attack strategy dimension ATa, attack technology dimension ATe, attack software and process dimension AP, attack impact dimension AI, attacker dimension TA, attack motivation dimension AM, actor ability dimension AA, and ATM system security guardian dimension ASG.

5. A construction method of a knowledge graph based on network threat of an air traffic control system according to claim 3, characterized in that The relationships between the entities include: AHA belongs to AC, AHA is located in AND, AHA exists in AV, ATe exploits AV, ATe threatens AHA, ATe obtains ATa, ATe executes AI, AV is located in AND, AV belongs to AC, AP completes ATe, AP obtains ATa, AP executes AI, TA owns AP, TA is used for AA, TA mines AM, TA exploits AV, TA is used for ATe, TA completes AI, ASG protects AHA, ASG repairs AV, ASG confronts ATe, ASG blocks Ata, AA depends on AV, AND belongs to AC.

6. A construction method of a knowledge graph based on network threat of an air traffic control system according to claim 1, characterized in that, The construction of the knowledge graph ATMCyKG through several entities and the relationships between the entities includes: Construct the knowledge graph ATMCyKG using the graph database software Neo4j according to several entities and the relationships between the entities.

7. A construction method of a knowledge graph based on network threat of an air traffic control system according to claim 6, characterized in that, The specific process of constructing the knowledge graph ATMCyKG using the graph database software Neo4j is: First step, environment configuration and preparation of CSV files; Second step, execute the import command; Third step, import of node data; Fourth step, import of relationship data; Fifth step, verify the execution result of the knowledge graph ATMCyKG.

8. A construction system based on an air traffic control system network threat knowledge graph, characterized in that, Including: A data collection module for obtaining various data of the ATM system under network threats; An entity analysis module for obtaining several entities under network threats to the ATM system and the relationships between the entities based on the various data of the ATM system; The knowledge graph construction module is used to construct the knowledge graph ATMCyKG through several entities and the relationships between the entities.

9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the method for constructing a knowledge graph based on the air traffic control system network threat knowledge graph according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method for constructing a knowledge graph based on the air traffic control system network threat knowledge graph according to any one of claims 1-7.