Host attack tracing method

The method addresses the challenges of tracing attackers by using data preprocessing, feature extraction, and machine learning to enhance the accuracy and speed of attacker identification and defensive actions in complex network environments.

CN120321040AInactive Publication Date: 2025-07-15BEIJING ANDY TECH CO LTD
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202510795951.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-07-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing host attack traceability methods are inefficient when processing massive network data, making it difficult to deal with rapidly changing network environments, and traditional methods are difficult to track new attacks and have low accuracy.

Method used

The methods of data collection and preprocessing, feature extraction and analysis, attack traceability and location, real-time response and defense, and continuous optimization are adopted, combined with machine learning models and rule bases, network data is analyzed in real time, the identity and location of the attacker are tracked, and defense measures are taken.

Benefits of technology

It improves the accuracy and real-time tracing of host attacks, can respond to new attacks in a timely manner, shortens traceability time, provides effective defense measures, and ensures network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321040A_ABST
    Figure CN120321040A_ABST
Patent Text Reader

Abstract

The invention discloses a host attack tracing method, which relates to the technical field of network security, and comprises the following steps: S1, collecting and preprocessing data; s2, feature extraction and analysis; s3, attack tracing and positioning; s4, performing real-time response and defense; and S5, continuously optimizing. According to the host attack tracing method, massive and complex network data can be efficiently processed, so that a rapidly changing network environment can be easily handled, potential attack behaviors are timely captured and analyzed, and the time interval from attack occurrence to tracing completion is greatly shortened. Meanwhile, according to the method, through the fine design of the steps of feature extraction and analysis, attack tracing and positioning and the like and the intelligent application of a machine learning model or a rule base, the tracing accuracy is greatly improved, various novel attacks can be coped, the real identity and position of an attacker can be accurately tracked, and powerful support is provided for fighting against network criminal activities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and specifically to a method for tracing the source of host attacks. Background Art

[0002] With the popularization of the Internet and the advent of the digital age, computer networks have become an indispensable part of modern society. However, with the expansion of the network scale and the increase in complexity, network security issues have become increasingly prominent. Therefore, it is particularly important to trace the source of host attacks.

[0003] The main purpose of tracing the source of host attacks is to track and locate attackers, understand the source, method, and purpose of attacks, so as to provide strong support for subsequent defense and response. Through source tracing, vulnerabilities can be discovered and repaired in a timely manner to prevent similar attacks from occurring again; at the same time, it can also provide clues for law enforcement agencies to combat cybercrime activities.

[0004] However, in the actual operation process, with the expansion of the network scale, the generated log and network traffic data are very large, making the analysis and source tracing work extremely difficult. Especially in the face of a rapidly changing network environment, existing source tracing methods often lag in processing speed and response time, unable to meet the requirements of real-time source tracing. At the same time, due to hackers constantly developing new attack means and technologies, traditional source tracing methods are difficult to cope with new types of attacks. Combined with the complexity of the network environment, it is even more difficult to accurately track the true identity and location of attackers, resulting in low source tracing accuracy. Summary of the Invention

[0005] The purpose of the present invention is to provide a method for tracing the source of host attacks to solve the problems raised in the above background art.

[0006] To achieve the above purpose, the present invention provides the following technical solution: A method for tracing the source of host attacks, including the following steps:

[0007] S1. Data collection and preprocessing: Real-time collect log data, traffic data, and the running status data of the host system in the network, and clean the collected data to remove invalid, duplicate, or incorrect data, and then perform standardization processing to ensure that data from different sources and in different formats can be uniformly analyzed and processed;

[0008] S2. Feature extraction and analysis: Extract features related to host attacks from the preprocessed data, such as abnormal access patterns, malicious code signatures, etc., and use the extracted features to combine with machine learning models and rule libraries to perform real-time analysis on network data to identify potential attack behaviors;

[0009] S3. Attack Tracing and Location: Based on the analyzed attack behaviors, trace the source of the attack, including the attacker's IP address, device information, etc., and combine the network topology structure and the configuration information of the host system to locate the true identity and location of the attacker;

[0010] S4. Real-time Response and Defense: According to the tracing results, take timely defense measures, such as blocking the attacker's IP address, isolating the infected host, etc., record and save the tracing results and defense measures in the form of reports or logs, and feedback them to the network security management system to provide a basis for formulating subsequent defense strategies;

[0011] S5. Continuous Optimization: Establish a tracing method evaluation system, regularly evaluate and optimize the tracing methods, and improve the accuracy and real-time performance of tracing.

[0012] Furthermore, in the step S1, data collection includes log data collection, traffic data collection, and host system running status data collection, specifically as follows:

[0013] Log data collection: Use a distributed log collection system (such as a log processing framework based on Hadoop or Spark) to achieve cross-node and cross-region log aggregation, and capture in real-time the log information generated by network devices (such as routers, switches, firewalls, etc.), servers, applications, etc. These logs record detailed information about network activities, such as user login attempts, network access requests, system errors, etc.;

[0014] Traffic data collection: Through network traffic analysis tools or sniffers, capture the packet traffic in the network in real-time, and use a distributed processing framework to perform real-time parsing and preliminary processing of the traffic data, supporting the filtering and collection of traffic for specific protocols, ports, or IP addresses. The traffic data provides real-time information about network communication, including source address, destination address, protocol type, packet size, etc.;

[0015] Host system running status data collection: Obtain the key performance indicators of the host system, such as CPU usage, memory occupancy, disk space, etc., in real-time through a remote monitoring agent or system API, and send the collected data to the distributed data collection system for further processing.

[0016] Furthermore, in the step S1, the specific operations of data preprocessing include the following:

[0017] Data cleaning: Use cleaning tools and algorithms such as regular expressions and data filtering to remove invalid, duplicate, or incorrect entries in the log and traffic data, perform outlier detection and correction on the host system running status data, and ensure the consistency and accuracy of the data;

[0018] Data standardization: Convert data from different sources and formats into a unified format and unit, define standard data models and data dictionaries to facilitate subsequent data analysis and processing, and implement data standardization using built-in functions of distributed processing frameworks such as Hadoop and Spark or custom scripts;

[0019] Data integration: Integrate the cleaned and standardized data into a unified data storage, such as a distributed file system (HDFS), a NoSQL database, etc., to facilitate subsequent data analysis, mining, and visualization.

[0020] Furthermore, in the step S2, the specific operation of feature extraction: According to the data type, select a feature extraction tool, and then extract features related to attack behaviors according to common patterns of host attacks. For example, abnormal access patterns (such as frequent failed login attempts, access to sensitive resources, etc.), malicious code signatures (such as specific file hash values, process behavior patterns, etc.), and use feature selection algorithms (such as chi-square test, mutual information, recursive feature elimination, etc.) to further screen key features to improve the performance and accuracy of the classifier.

[0021] Furthermore, the selection of the feature extraction tool is as follows:

[0022] For text data (such as log information), use TF-IDF (term frequency-inverse document frequency) to measure the importance of vocabulary, or use word embedding techniques such as Word2Vec to convert the text into a vector representation for subsequent analysis;

[0023] For numerical data (such as traffic statistics, system performance metrics), directly use the standardized numerical values as features;

[0024] For time series data, extract statistical features (such as mean, variance, maximum value, minimum value, etc.) or use time series analysis techniques to extract features such as trends and seasonality.

[0025] Furthermore, in the step S2, deploy the trained machine learning model or rule library to the network security monitoring system for real-time analysis of network data. When a potential attack behavior is detected, trigger an alarm and provide detailed attack information.

[0026] Furthermore, in the step S3, attack tracing includes two major items: IP address tracing and device information tracing. The IP address tracing uses IP address library query, IP address reverse resolution, and AS number query techniques to trace the attacker's IP address. The specific process is as follows:

[0027] IP address library query: Use a known IP address library (such as an IP geographical location database) to query the attacker's IP address and obtain its approximate geographical location information;

[0028] IP address reverse resolution: Obtain domain name information associated with the attacker's IP address through DNS reverse resolution (such as using the nslookup or dig commands) to further understand the attacker's background;

[0029] AS number query: Query the autonomous system (AS) number to which the attacker's IP address belongs to obtain the network service provider used by the attacker;

[0030] The device information tracking: In the case where the attack involves specific devices (such as infected hosts in a botnet), further track the source of the attack by analyzing device information (such as MAC address, operating system version, hardware configuration, etc.).

[0031] Furthermore, in step S3, the specific process of attack localization is as follows:

[0032] 1) Network topology analysis: Use network topology analysis tools such as NetworkX (for network analysis and visualization) and Gephi (for complex network analysis) to construct and analyze the network topology structure, identify the attack path and propagation method, and combine network logs to analyze the log information of network devices (such as routers, switches) to obtain the propagation path and key nodes of the attack traffic in the network;

[0033] 2) Analysis of host system configuration information:

[0034] System log review: Review the system logs of the attacked host (such as Windows Event Viewer, Linux syslog, etc.) to obtain detailed information about the attacker's activities such as logging in and executing commands.

[0035] File integrity check: Use file integrity verification tools (such as tripwire, AIDE, etc.) to check whether the key files on the attacked host have been tampered with or deleted;

[0036] Process and network connection analysis: Analyze the process list and network connection information on the attacked host to identify abnormal processes and suspicious network connections;

[0037] 3) Comprehensive analysis and localization:

[0038] Integrate the IP address tracking results, network topology analysis results, and host system configuration information analysis results to form a complete view of the attack chain;

[0039] By analyzing the key nodes in the attack chain and the attacker's behavior pattern, gradually narrow down the scope of the attacker's identity and location.

[0040] Further, in step S4, network security defense tools such as firewalls and intrusion detection systems (IDS) are used to achieve real-time response and defense, which specifically include the following defense measures:

[0041] IP address blocking: For the confirmed attacker IP addresses, immediately set up an access control list (ACL) on the firewall or router to prevent further communication from these IPs.

[0042] Network isolation: Isolate the entire attacked network segment or subnet to prevent the attack from spreading within the network.

[0043] Host isolation: Remove the confirmed infected hosts from the network or place them in an isolated network environment to prevent the further spread of malware or attack code.

[0044] Service suspension: If the attack involves specific services (such as web servers, databases, etc.), temporarily shut down these services to reduce the attack surface.

[0045] Further, in step S5, the construction of the traceability method evaluation system includes:

[0046] 1) Evaluation index setting

[0047] Accuracy: Evaluate the matching degree between the traceability information and the actual production process and product information.

[0048] Real-time performance: Measure the speed of traceability information update and the timeliness of responding to consumer or regulatory requirements.

[0049] Integrity: Ensure that the traceability information covers the whole process from raw material procurement to product sales.

[0050] Security: Ensure that the traceability data is not tampered with or leaked, and adopt encryption technology and secure storage measures.

[0051] Efficiency: Improve the efficiency of the traceability process, reduce unnecessary links and costs.

[0052] 2) Evaluation methods

[0053] Regular audit: Conduct a comprehensive audit of the traceability process every quarter or year, including aspects such as information recording, identification management, data collection, and traceability systems.

[0054] On-site inspection: Conduct on-site inspections of the production site to ensure the authenticity and accuracy of the traceability information.

[0055] Customer feedback: Collect consumers' satisfaction and feedback on the traceability information as the basis for evaluation and improvement.

[0056] Third-party certification: Invite a third-party agency to certify the traceability process to ensure compliance with industry standards and regulatory requirements;

[0057] 3) Evaluation report

[0058] After each evaluation, prepare a detailed evaluation report to summarize the advantages and disadvantages of the traceability process and propose improvement measures and suggestions.

[0059] The present invention provides a host attack traceability method, which has the following beneficial effects:

[0060] The present invention can efficiently process massive and complex network data, thus easily coping with the rapidly changing network environment, timely capturing and analyzing potential attack behaviors, and greatly shortening the time interval from the occurrence of an attack to the completion of traceability. At the same time, through the refined design of steps such as feature extraction and analysis, attack traceability and positioning, and combined with the intelligent application of machine learning models or rule bases, the traceability accuracy of this method is greatly improved, and it can cope with various new attacks, accurately track the true identity and location of the attacker, and provide strong support for combating cybercrime activities. In addition, according to the traceability results, this method can quickly take targeted defense measures to effectively prevent the further spread and harm of attack behaviors. It also has the ability of continuous optimization and update, regularly evaluating and optimizing the traceability method to ensure that the traceability method and defense strategy always keep pace with the times, so that this method can maintain high-efficiency and accurate traceability effects for a long time and provide continuous guarantee for network security. Brief description of the drawings

[0061] Figure 1 It is a schematic flow chart of the steps of the host attack traceability method of the present invention;

[0062] Figure 2 It is a logic block diagram of attack traceability of the host attack traceability method of the present invention. Specific embodiments

[0063] The following further describes the embodiments of the present invention in detail with reference to the drawings and embodiments. The following embodiments are used to illustrate the present invention, but cannot be used to limit the scope of the present invention.

[0064] As Figure 1 - Figure 2 shown, the host attack traceability method includes the following steps:

[0065] S1. Data collection and preprocessing:

[0066] Real-time collect log data, traffic data, and the running status data of host systems in the network, and clean the collected data to remove invalid, duplicate, or incorrect data, and then perform standardization processing to ensure that data from different sources and in different formats can be uniformly analyzed and processed. This step uses distributed data collection systems such as Hadoop and Spark, combined with data cleaning tools and algorithms, to achieve efficient and accurate data collection and preprocessing, providing strong support for network security monitoring and analysis.

[0067] In this embodiment, data collection includes log data collection, traffic data collection, and host system running status data collection, which are specifically as follows:

[0068] Log data collection: Use a distributed log collection system (such as a log processing framework based on Hadoop or Spark) to achieve cross-node and cross-region log aggregation, and real-time capture log information generated by network devices (such as routers, switches, firewalls, etc.), servers, applications, etc. These logs record detailed information about network activities, such as user login attempts, network access requests, system errors, etc.;

[0069] Traffic data collection: Through network traffic analysis tools or sniffers, real-time capture the packet traffic in the network, and use a distributed processing framework to perform real-time parsing and preliminary processing of the traffic data, supporting the filtering and collection of traffic for specific protocols, ports, or IP addresses. Traffic data provides real-time information about network communication, including source address, destination address, protocol type, packet size, etc.;

[0070] Host system running status data collection: Real-time obtain the key performance indicators of the host system, such as CPU usage, memory occupancy, disk space, etc., through remote monitoring agents or system APIs, and send the collected data to the distributed data collection system for further processing.

[0071] In this embodiment, the specific data preprocessing includes the following operations:

[0072] Data cleaning: Use cleaning tools and algorithms such as regular expressions and data filtering to remove invalid, duplicate, or incorrect entries in the log and traffic data, and perform outlier detection and correction on the host system running status data to ensure data consistency and accuracy;

[0073] Data standardization: Convert data from different sources and in different formats into a unified format and unit, define a standard data model and data dictionary, facilitate subsequent data analysis and processing, and use the built-in functions or custom scripts of distributed processing frameworks such as Hadoop and Spark to achieve data standardization;

[0074] Data integration: Integrate the cleaned and standardized data into a unified data storage, such as a distributed file system (HDFS), a NoSQL database, etc., to facilitate subsequent data analysis, mining, and visualization.

[0075] S2. Feature extraction and analysis:

[0076] Extract features related to host attacks from the preprocessed data, such as abnormal access patterns, malicious code signatures, etc. Then, using the extracted features, combine with machine learning models (train models using machine learning frameworks such as TensorFlow, PyTorch. The selected model types include logistic regression, support vector machines, random forests, neural networks, etc., depending on the characteristics of the data and the complexity of the problem. During the training process, adjust the model parameters, select appropriate optimization algorithms, and perform steps such as cross-validation to ensure the accuracy and generalization ability of the model) and a rule base (build a rule-based detection system, such as using the rule base of an intrusion detection system (IDS) like Snort. These rules are defined based on known attack patterns, malicious code signatures, or abnormal behavior patterns and are updated regularly to address new threats) to perform real-time analysis on network data and identify potential attack behaviors.

[0077] In this embodiment, the specific operation of feature extraction: According to the data type, select a feature extraction tool, and then according to the common patterns of host attacks, extract features related to attack behaviors. For example, abnormal access patterns (such as frequent failed login attempts, accessing sensitive resources, etc.), malicious code signatures (such as specific file hash values, process behavior patterns, etc.), and use feature selection algorithms (such as chi-square test, mutual information, recursive feature elimination, etc.) to further screen key features to improve the performance and accuracy of the classifier. Among them, the selection of feature extraction tools is as follows:

[0078] For text data (such as log information), use TF-IDF (term frequency-inverse document frequency) to measure the importance of vocabulary, or use word embedding techniques such as Word2Vec to convert the text into a vector representation for subsequent analysis;

[0079] For numerical data (such as traffic statistics, system performance metrics), directly use the standardized numerical values as features;

[0080] For time series data, extract statistical features (such as mean, variance, maximum, minimum, etc.) or use time series analysis techniques to extract features such as trends and seasonality.

[0081] In this embodiment, deploy the trained machine learning model or rule base to the network security monitoring system for real-time analysis of network data. When potential attack behaviors are detected, trigger an alarm and provide detailed attack information.

[0082] S3. Attack Tracing and Location:

[0083] Based on the analyzed attack behaviors, trace the source of the attack, including the attacker's IP address, device information, etc., and combine the network topology structure and the configuration information of the host system to locate the real identity and location of the attacker.

[0084] In this embodiment, attack tracing includes two major items: IP address tracing and device information tracing. IP address tracing uses IP address library query, IP address reverse resolution, and AS number query technologies to trace the attacker's IP address. The specific process is as follows:

[0085] IP address library query: Use a known IP address library (such as an IP geographical location database) to query the attacker's IP address and obtain its approximate geographical location information;

[0086] IP address reverse resolution: Obtain domain name information associated with the attacker's IP address through DNS reverse resolution (such as using the nslookup or dig commands) to further understand the attacker's background;

[0087] AS number query: Query the autonomous system (AS) number to which the attacker's IP address belongs to obtain the network service provider used by the attacker;

[0088] Device information tracing: In the case where the attack involves specific devices (such as infected hosts in a botnet), further trace the source of the attack by analyzing device information (such as MAC address, operating system version, hardware configuration, etc.).

[0089] In this embodiment, the specific process of attack location:

[0090] 1) Network topology analysis: Use network topology analysis tools, such as NetworkX (for network analysis and visualization) and Gephi (for complex network analysis), to construct and analyze the network topology structure, identify the attack path and propagation method, and combine network logs to analyze the log information of network devices (such as routers, switches) to obtain the propagation path and key nodes of the attack traffic in the network;

[0091] 2) Analysis of host system configuration information:

[0092] System log review: Review the system logs of the attacked host (such as Windows Event Viewer, Linux syslog, etc.) to obtain detailed information about the attacker's activities such as logging in and executing commands.

[0093] File integrity check: Use file integrity verification tools (such as tripwire, AIDE, etc.) to check whether critical files on the attacked host have been tampered with or deleted;

[0094] Process and network connection analysis: Analyze the process list and network connection information on the attacked host to identify abnormal processes and suspicious network connections;

[0095] 3) Comprehensive analysis and location:

[0096] Integrate the IP address tracing results, network topology analysis results, and host system configuration information analysis results to form a complete view of the attack chain;

[0097] By analyzing the key nodes in the attack chain and the attacker's behavior patterns, gradually narrow down the scope of the attacker's identity and location.

[0098] S4, Real-time response and defense:

[0099] According to the tracing results, take timely defense measures, such as blocking the attacker's IP address, isolating the infected host, etc., record and save the tracing results and defense measures in the form of reports or logs, and feedback them to the network security management system to provide a basis for formulating subsequent defense strategies.

[0100] In this embodiment, use network security defense tools, such as firewalls, intrusion detection systems (IDS), etc., to achieve real-time response and defense, specifically including the following defense measures:

[0101] IP address blocking: For the confirmed attacker IP addresses, immediately set up an access control list (ACL) on the firewall or router to prevent further communication from these IPs;

[0102] Network isolation: Isolate the entire attacked network segment or subnet to prevent the attack from spreading within the network;

[0103] Host isolation: Remove the confirmed infected host from the network or place it in an isolated network environment to prevent the further spread of malware or attack code;

[0104] Service suspension: If the attack involves specific services (such as web servers, databases, etc.), temporarily shut down these services to reduce the attack surface.

[0105] S5, Continuous optimization:

[0106] Establish a tracing method evaluation system, regularly evaluate and optimize the tracing methods, and improve the accuracy and real-time performance of tracing. In this step, the construction of the tracing method evaluation system includes:

[0107] 1) Setting of evaluation indicators

[0108] Accuracy: Evaluate the matching degree between the traceability information and the actual production process and product information;

[0109] Real-time performance: Measure the speed of traceability information update and the timeliness of responding to consumer or regulatory requirements;

[0110] Integrity: Ensure that the traceability information covers the whole process from raw material procurement to product sales;

[0111] Security: Guarantee that the traceability data is not tampered with or leaked, and adopt encryption technology and secure storage measures;

[0112] Efficiency: Improve the efficiency of the traceability process, and reduce unnecessary links and costs;

[0113] 2) Evaluation methods

[0114] Regular audits: Conduct a comprehensive audit of the traceability process every quarter or year, including aspects such as information recording, label management, data collection, and traceability systems;

[0115] On-site inspections: Conduct on-site inspections of the production site to ensure the authenticity and accuracy of the traceability information;

[0116] Customer feedback: Collect consumers' satisfaction and feedback on the traceability information, and use it as the basis for evaluation and improvement;

[0117] Third-party certification: Invite a third-party agency to certify the traceability process to ensure compliance with industry standards and regulatory requirements;

[0118] 3) Evaluation reports

[0119] After each evaluation, prepare a detailed evaluation report, summarize the advantages and disadvantages of the traceability process, and put forward improvement measures and suggestions.

[0120] The embodiments of the present invention are given for purposes of illustration and description, and are not exhaustive or limit the present invention to the disclosed form. Many modifications and variations are obvious to those of ordinary skill in the art. The embodiments are chosen and described in order to better illustrate the principles of the present invention and its practical applications, and to enable those of ordinary skill in the art to understand the present invention and design various embodiments with various modifications suitable for specific purposes.

Claims

1. A method for tracing the source of a host attack, characterized in that, It includes the following steps: S1. Data collection and preprocessing: Collect log data, traffic data, and the running status data of the host system in real time, and clean and standardize the collected data; S2. Feature extraction and analysis: Extract features related to host attacks from the preprocessed data, and use the extracted features, combined with machine learning models and rule libraries, to perform real-time analysis on network data to identify potential attack behaviors; S3. Attack tracing and positioning: According to the analyzed attack behaviors, trace the source of the attack, and combine the network topology structure and the configuration information of the host system to locate the true identity and location of the attacker; S4. Real-time response and defense: According to the tracing results, take defense measures in a timely manner, and feedback the tracing results and defense measures to the network security management system; S5. Continuous optimization: Establish an evaluation system for tracing methods, and regularly evaluate and optimize the tracing methods.

2. The host attack traceability method according to claim 1, characterized in that In the step S1, data collection includes log data collection, traffic data collection, and the running status data collection of the host system, specifically as follows: Log data collection: Use a distributed log collection system to achieve cross-node and cross-region log aggregation, and capture the log information generated by network devices, servers, and applications in real time; Traffic data collection: Through network traffic analysis tools or sniffers, capture the packet traffic in the network in real time, and use a distributed processing framework to perform real-time parsing and preliminary processing on the traffic data, supporting the filtering and collection of traffic for specific protocols, ports, or IP addresses; Running status data collection of the host system: Obtain the key performance indicators of the host system in real time through a remote monitoring agent or system API, and send the collected data to a distributed data collection system for further processing.

3. The host attack traceability method according to claim 1, wherein In the step S1, the specific operations of data preprocessing include the following: Data cleaning: Use cleaning tools and algorithms to remove invalid, duplicate, or incorrect entries in the log and traffic data, and perform outlier detection and correction on the running status data of the host system; Data standardization: Convert data from different sources and different formats into a unified format and unit, define a standard data model and data dictionary, and use the built-in functions or custom scripts of the distributed processing framework to achieve data standardization; Data integration: Integrate the cleaned and standardized data into a unified data storage.

4. The host attack traceability method according to claim 1, characterized in that In the step S2, the specific operations of feature extraction: According to the data type, select a feature extraction tool, and then extract features related to attack behaviors according to the common patterns of host attacks, and further screen key features using a feature selection algorithm.

5. The host attack traceability method according to claim 4, wherein, The selection of the feature extraction tool is as follows: For text data, use TF-IDF to measure the importance of vocabulary, or use word embedding technology to convert the text into a vector representation; For numerical data, directly use the standardized numerical values as features; For time series data, extract statistical features or use time series analysis techniques to extract trends and seasonal features.

6. The host attack traceability method according to claim 1, characterized in that, In step S2, the trained machine learning model or rule base is deployed into the network security monitoring system for real-time analysis of network data. When potential attack behaviors are detected, an alarm is triggered and detailed attack information is provided.

7. The host attack traceability method according to claim 1, characterized in that In step S3, attack traceability includes two major items: IP address tracing and device information tracing. The IP address tracing uses IP address library query, IP address reverse resolution, and AS number query technologies to trace the attacker's IP address. The specific process is as follows: IP address library query: Use the known IP address library to query the attacker's IP address and obtain its approximate geographical location information. IP address reverse resolution: Obtain the domain name information associated with the attacker's IP address through DNS reverse resolution to further understand the attacker's background. AS number query: Query the autonomous system number to which the attacker's IP address belongs to obtain the network service provider used by the attacker. The device information tracing: In the case where the attack involves specific devices, analyze the device information to further trace the source of the attack.

8. The host attack traceability method according to claim 1, wherein In step S3, the specific process of attack localization: 1) Network topology analysis: Use network topology analysis tools to construct and analyze the network topology structure, identify the attack path and propagation method, and combine network logs to analyze the log information of network devices to obtain the propagation path and key nodes of the attack traffic in the network. 2) Analysis of host system configuration information: System log review: Review the system logs of the attacked host to obtain detailed information about the attacker's activities. File integrity check: Use file integrity verification tools to check whether the key files on the attacked host have been tampered with or deleted. Process and network connection analysis: Analyze the process list and network connection information on the attacked host to identify abnormal processes and suspicious network connections. 3) Comprehensive analysis and localization: Integrate the IP address tracing results, network topology analysis results, and host system configuration information analysis results to form a complete view of the attack chain. By analyzing the key nodes in the attack chain and the attacker's behavior patterns, gradually narrow down the scope of the attacker's identity and location.

9. The host attack traceability method according to claim 1, wherein In step S4, use network security defense tools to achieve real-time response and defense, which specifically includes the following defense measures: IP address blocking: For the confirmed attacker's IP address, immediately set up an access control list on the firewall or router. Network isolation: Isolate the entire attacked network segment or subnet. Host isolation: Remove the confirmed infected host from the network or place it in an isolated network environment. Service suspension: If the attack involves specific services, temporarily shut down these services.

10. The host attack traceability method according to claim 1, characterized in that, In step S5, the construction of the traceability method evaluation system includes: 1) Setting of evaluation indicators Accuracy: Evaluate the matching degree between the traceability information and the actual production process and product information. Real-time performance: Measure the update speed of the traceability information and the timeliness of responding to consumer or regulatory requirements. Integrity: Ensure that the traceability information covers the entire process from raw material procurement to product sales. Security: Ensure that the traceability data is not tampered with or leaked, and adopt encryption technology and secure storage measures. Efficiency: Improve the efficiency of the traceability process and reduce unnecessary links and costs; 2) Evaluation methods Regular audits: Conduct comprehensive audits of the traceability process quarterly or annually, including information recording, identification management, data collection, and traceability systems; On-site inspections: Conduct on-site inspections of the production site to ensure the authenticity and accuracy of traceability information; Customer feedback: Collect consumers' satisfaction and feedback on traceability information as the basis for evaluation and improvement; Third-party certification: Invite a third-party agency to certify the traceability process to ensure compliance with industry standards and regulatory requirements; 3) Evaluation report After each evaluation, prepare a detailed evaluation report to summarize the advantages and disadvantages of the traceability process and propose improvement measures and suggestions.

Citation Information

Patent Citations

  • Mobile phone positioning method and system

    CN104202819A

  • Flow positioning method, device and system

    CN105591765A

  • Tracking and positioning monitoring method and intelligent wearable device, positioner and server

    CN105759297A

  • Moving-target tracking method and device of unmanned aerial vehicle

    CN106482729A

  • A method and a system for positioning personnel in space based on mobile phone positioning

    CN109922438A