Encrypted ransomware attack rapid detection method and system based on semantic traceability graph
Through the encryption ransomware attack detection method based on semantic traceability map, combined with high-speed and deep detection, the rapid identification and accurate response to encrypted ransomware attacks are achieved, solving the problems of low lag and accuracy in the existing detection methods, and improving detection efficiency and accuracy.
Patent Information
- Application Number
- CN202510583885.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-07-18
AI Technical Summary
The existing encryption ransomware attack detection methods have the problem of high detection lag and low detection accuracy, especially in the early stages of insufficient characteristics, resulting in high missed rate and long detection time.
A fast detection method based on semantic traceability map is adopted, and the preprocessed mixed log stream is performed with high-speed detection and deep detection, combined with malicious command matching, blacklist keyword detection and semantic traceability map generation, and the detection process is optimized by the embedded vector database to achieve a deep fusion of real-time rule matching and semantic behavior correlation analysis.
It significantly improves the detection accuracy of encrypted ransomware attacks, reduces detection lag, shortens the delay in handling key threats, enhances the coverage of advanced threat semantic links, and optimizes the false positive trade-offs and computing power consumption of traditional detection mechanisms.
Smart Images

Figure CN120342733A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a method and system for quickly detecting encrypted ransom attacks based on a semantic traceability graph. Background Art
[0002] Encrypted ransom attacks use an attack mode of encrypting critical data to extort ransom. Attackers quickly control the target system through complex penetration means, making it impossible for victims to access core data or critical business systems unless they pay a high ransom for decryption. This has caused systematic impacts on key fields such as manufacturing, energy, and finance, and seriously weakened the security and stability of infrastructure. Compared with traditional network attacks, encrypted ransom attacks have the characteristics of rapid spread, deep concealment, and difficulty in recovery. Attackers use new attack paradigms such as dynamically combining intrusion paths and disguising operation behaviors to continuously bypass traditional protection systems based on signature matching, resulting in frequent major security incidents and posing severe challenges to the existing network security defense system.
[0003] Currently, conventional methods for detecting encrypted ransom attacks include traceability graph analysis. A traceability graph is a graphical structure widely used to describe and trace the process of network attacks, the behaviors of attackers, and their relationships with the target system, and is an important tool in the field of attack detection. In the form of nodes and edges, the traceability graph shows the steps and their interconnections of how attackers penetrate the target system from the starting point and finally achieve the attack goal. Each node usually represents an attack event, behavior, or system component, while the edge represents the causal or dependency relationship between different nodes. The traceability graph can not only provide a rich information chain but also help quickly identify the attack path.
[0004] However, there are still some problems with the above-mentioned conventional methods for detecting encrypted ransom attacks. For example, the existing methods for detecting encrypted ransom attacks rely on traceability graphs for analysis and detection, resulting in a problem of explosion of dependencies, significantly increasing the data scale and computational overhead, with long detection time and low efficiency, and insufficient attention to the characteristics in the early stage of the attack, leading to a high false negative rate, lagging attack detection, and inability to respond in a timely manner. Summary of the Invention
[0005] In order to solve the above problems existing in the prior art, the present invention provides a method and system for quickly detecting encrypted ransom attacks based on a semantic traceability graph. The technical problems to be solved by the present invention are realized through the following technical solutions:
[0006] In a first aspect, the present invention provides a method for quickly detecting encrypted ransom attacks based on a semantic traceability graph, including: obtaining a preprocessed mixed log stream; synchronously performing high-speed detection and in-depth detection on the preprocessed mixed log stream to obtain corresponding high-speed detection results and in-depth detection results; in the case that the high-speed detection result indicates the existence of an encrypted ransom attack behavior, stopping all detections and triggering an alarm; in the case that the high-speed detection result indicates the non-existence of an encrypted ransom attack behavior, continuing to perform the in-depth detection to determine whether to trigger an alarm according to the in-depth detection result; wherein, the high-speed detection result is obtained by performing malicious command matching and blacklist keyword detection on the preprocessed mixed log stream; wherein, the in-depth detection result is obtained through the following steps: respectively extracting semantic information related to encrypted ransom attack behaviors from the preprocessed mixed log stream to generate an optimized semantic traceability graph; determining the matching result between the optimized semantic traceability graph and an embedded vector database based on a preset mapping rule; obtaining the embedded vector corresponding to the optimized semantic traceability graph according to the matching result; and identifying the embedded vector corresponding to the optimized semantic traceability graph to obtain the in-depth detection result.
[0007] Optimally, the preprocessed mixed log stream includes: a system log stream and an application program log stream; the step of respectively extracting semantic information related to encrypted ransom attack behaviors from the preprocessed mixed log stream to generate an optimized semantic traceability graph includes: using regular expressions to extract multiple preset type fields from the system log stream; using a parse tree to obtain multiple template fields from the application program log stream; generating a system traceability graph based on the multiple preset type fields, where the multiple preset type fields are the vertices of the system traceability graph, and the interaction relationship between adjacent two preset type fields is used as the edge information of the system traceability graph; according to a predefined association mapping rule, associating the multiple template fields with the system traceability graph to obtain a semantic traceability graph; performing redundant edge pruning and duplicate edge merging on the semantic traceability graph to reduce the semantic traceability graph and obtain the optimized semantic traceability graph.
[0008] Optimally, the step of according to a predefined association mapping rule, associating the multiple template fields with the system traceability graph to obtain a semantic traceability graph includes: traversing the multiple preset type fields and the multiple template fields, and screening out the common fields between the two; based on the common fields, associating the corresponding template fields in the multiple template fields with the vertices and edge information of the system traceability graph; and expanding the template fields in the multiple template fields other than the common fields into new vertices and new edge information of the system traceability graph to obtain the semantic traceability graph.
[0009] Optimally, the embedded vector database is obtained through the following steps: obtaining a data set mixed with multiple encrypted ransomware attack data and multiple benign software behavior data; using the data set to generate a retrieval semantic traceability graph; using a word vector model to convert the retrieval semantic traceability graph into multiple word embedded vectors; using a graph representation learning model based on an average aggregation method to process the multiple word embedded vectors to obtain multiple learned embedded vectors; storing the multiple learned embedded vectors to obtain the embedded vector database.
[0010] Optimally, obtaining the embedded vector corresponding to the optimized semantic traceability graph according to the matching result includes: when the matching result is a match, obtaining the corresponding multiple learned embedded vectors in the embedded vector database as the embedded vector corresponding to the optimized semantic traceability graph; when the matching result is a mismatch, using a word vector model and a graph representation learning model based on an average aggregation method to convert the optimized semantic traceability graph into multiple retrieval embedded vectors.
[0011] Optimally, the learned embedded vector corresponding to vertex v at the k+1 layer satisfies the expression:
[0012]
[0013] where W (k) is the existing learnable weight matrix in the graph representation learning model, used to map the aggregated features to a new embedding space, k∈1,...,K, σ is a non-linear activation function, AGGREGATE k (·) is an aggregation function used to aggregate the embedding information of vertex v and the neighbor vertices in the k-th iteration, is the feature representation of neighbor vertex u in the k-th iteration, N(v) is the set of neighbors of vertex v in the optimized semantic traceability graph, and v is a positive integer.
[0014] Optimally, the preprocessing includes: duplicate removal processing, normalization processing, and outlier processing.
[0015] Optimally, the preset type fields at least include: file operation information, process execution information, and network activity information.
[0016] Second aspect, the present invention provides a rapid detection system for encrypted ransom attacks based on a semantic traceability graph. The rapid detection system for encrypted ransom attacks is used to implement the rapid detection method for encrypted ransom attacks based on a semantic traceability graph described in the first aspect above. The rapid detection system for encrypted ransom attacks includes: a data acquisition unit and a detection unit. The data acquisition unit is used to acquire the preprocessed mixed log stream. The detection unit is used to perform high-speed detection and in-depth detection on the preprocessed mixed log stream simultaneously, and obtain corresponding high-speed detection results and in-depth detection results. Among them, the priority of the high-speed detection results is higher than that of the in-depth detection results. Among them, the high-speed detection includes: malicious command matching and blacklist keyword detection. Among them, the high-speed detection results are obtained by performing malicious command matching and blacklist keyword detection on the preprocessed mixed log stream. Among them, the in-depth detection results are obtained by the following method: respectively extract the semantic information related to encrypted ransom attack behaviors in the preprocessed mixed log stream to generate an optimized semantic traceability graph; based on a preset mapping rule, determine the matching result between the optimized semantic traceability graph and the embedded vector database; according to the matching result, obtain the embedded vector corresponding to the optimized semantic traceability graph; identify the embedded vector corresponding to the optimized semantic traceability graph to obtain the in-depth detection results. The detection unit is also used to stop all detections and trigger an alarm when the high-speed detection results indicate the existence of encrypted ransom attack behaviors. The detection unit is also used to continue to perform the in-depth detection when the high-speed detection results indicate the non-existence of encrypted ransom attack behaviors, so as to determine whether to trigger an alarm according to the in-depth detection results.
[0017] Optimally, the rapid detection system for encrypted ransom attacks further includes: a semantic traceability graph generation unit. The semantic traceability graph generation unit is used to extract multiple preset type fields in the system log stream by using regular expressions; obtain multiple template fields in the application program log stream by using a parse tree; based on the multiple preset type fields, generate a system traceability graph, where the multiple preset type fields are the vertices of the system traceability graph, and the interaction relationship between two adjacent preset type fields is used as the edge information of the system traceability graph; according to a predefined association mapping rule, associate the multiple template fields with the system traceability graph to obtain a semantic traceability graph; perform redundant edge pruning and duplicate edge merging on the semantic traceability graph to reduce the semantic traceability graph and obtain the optimized semantic traceability graph.
[0018] Compared with the prior art, the beneficial effects of the present invention are:
[0019] Aiming at the problems of high detection latency and low detection accuracy existing in the existing encryption ransomware attack detection methods, the present invention provides a fast detection method and system for encryption ransomware attacks based on a semantic traceability graph. This method deeply integrates real-time rule matching and semantic behavior correlation analysis through a task priority dynamic scheduling mechanism: First, based on the preprocessed hybrid log stream, high-speed detection (template-based rapid screening based on blacklist keywords and static features of malicious commands) and in-depth detection (construction of a semantic traceability graph and vectorized comparison, generating a deep threat graph by mining the behavior correlations among process chains, file operations, and network communications) are synchronously triggered; the two are combined to form a hierarchical collaborative defense - when the high-speed detection engine identifies an encryption ransomware attack, it immediately intercepts and alarms, shortening the latency of key threat handling. If the encryption ransomware attack is not identified, the in-depth detection continues, generating a semantic traceability graph for the preprocessed hybrid log stream to capture the encryption ransomware attack. Through the joint operation of moving the attack front forward and precisely deconstructing behaviors, while ensuring the real-time blocking effectiveness, it expands the coverage of the semantic links of advanced threats, significantly optimizing the inherent contradictions among false alarm trade-off, computing power consumption, and the ability to capture hidden threats in traditional single detection mechanisms, realizing a leap in defense energy efficiency from discrete rule matching to high-order context reasoning, effectively improving the detection accuracy and reducing the detection latency. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 FIG. is a schematic flowchart of a fast detection method for encryption ransomware attacks based on a semantic traceability graph provided by an embodiment of the present invention;
[0021] Figure 2 FIG. is a flowchart of extracting template fields in an application program log stream using a parse tree provided by an embodiment of the present invention;
[0022] Figure 3 FIG. is an example diagram of the generation of a semantic traceability graph provided by an embodiment of the present invention;
[0023] Figure 4 FIG. is an application example diagram of a fast detection method for encryption ransomware attacks based on a semantic traceability graph provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] The present invention will be further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.
[0025] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0026] Now, in conjunction with the accompanying drawings, a method and system for quickly detecting encrypted ransom attacks based on a semantic traceability graph provided by the present invention will be described in detail.
[0027] Figure 1 It is a schematic flowchart of a method for quickly detecting encrypted ransom attacks based on a semantic traceability graph provided by an embodiment of the present invention. As Figure 1 shown, the method includes:
[0028] Step 110: Obtain the preprocessed mixed log stream.
[0029] Here, the log types include: Shell history logs (for example, ~ / .bash_history in the Linux system, PowerShell event logs in the Windows system), system audit logs (for example, in the Linux system, the system audit logs can be directly viewed through auditd, and in the Windows system, ETW is used to trace the system audit logs), process monitoring logs, and network logs.
[0030] Among them, ETW, the full English name is Event Tracing for Windows, is a high-performance event tracing framework built into the Windows system for recording runtime events of the system and applications. It supports real-time monitoring and offline analysis and is widely used in scenarios such as performance analysis, troubleshooting, and security auditing. auditd is a daemon process on the Linux system for recording system audit logs. By monitoring events such as file access, user commands, and permission changes, it helps administrators with security auditing, troubleshooting, and compliance checks.
[0031] After obtaining the log stream mixed with system logs and application logs, perform deduplication processing, normalization processing, and outlier processing on the mixed log stream to obtain the preprocessed mixed log stream. The preprocessed mixed log stream includes: a system log stream and an application log stream.
[0032] Step 120: Perform high-speed detection and in-depth detection on the preprocessed hybrid log stream to obtain corresponding high-speed detection results and in-depth detection results.
[0033] Here, since the speed of high-speed detection is greater than that of in-depth detection, therefore, steps 130 or 140 are preferentially selected for execution according to the high-speed detection results.
[0034] Among them, the high-speed detection results are obtained by performing malicious command matching and blacklist keyword detection on the preprocessed hybrid log stream.
[0035] Exemplarily, when performing high-speed detection on the preprocessed hybrid log stream, first unify the field formats such as timestamps, hostnames, users, etc. in the log stream, and then extract key fields. For example, command content, executing user, process path, target IP / port, etc.; after obtaining the key fields, perform static feature matching based on regular expressions and string rules. For example, detect destructive operations such as rm -rf / and nc -e / bin / sh or reverse Shell commands, or scan known malicious domains (http: / / malware.com), suspicious file downloads (.sh|.exe), and abnormal permission changes (chmod 777) through a blacklist library (such as the Sigma rule set). At the same time, combined with dynamic context analysis, identify behavior patterns such as low-privilege users executing privileged commands, non-interactive environments triggering sensitive operations, and abnormal command sequences (such as consecutive port scans → privilege escalation → external connection within a short period of time) to obtain high-speed detection results.
[0036] Among them, the in-depth detection results are obtained through the following method: respectively extract the semantic information related to encrypted ransomware attack behaviors in the preprocessed hybrid log stream to generate an optimized semantic traceability graph; based on preset mapping rules, determine the matching result between the optimized semantic traceability graph and the embedded vector database; according to the matching result, obtain the embedded vector corresponding to the optimized semantic traceability graph; identify the embedded vector corresponding to the optimized semantic traceability graph to obtain the in-depth detection results.
[0037] Now, according to the acquisition process, each step of the in-depth detection will be described.
[0038] During the above operation of obtaining the depth detection result, semantic information related to encrypted ransomware attack behavior is extracted from the preprocessed mixed log stream respectively to generate an optimized semantic traceability graph, including: using regular expressions to extract multiple preset type fields from the system log stream; using a parse tree to obtain multiple template fields from the application log stream; generating a system traceability graph based on the multiple preset type fields, where the multiple preset type fields are the vertices of the system traceability graph, and the interaction relationship between two adjacent preset type fields is used as the edge information of the system traceability graph; according to the predefined association mapping rules, associating the multiple template fields with the system traceability graph to obtain a semantic traceability graph; pruning redundant edges and merging duplicate edges in the semantic traceability graph to reduce the semantic traceability graph and obtain an optimized semantic traceability graph.
[0039] It should be noted that the methods for extracting key fields from the system log stream and the application log stream are different. The system log stream is extracted using regular expressions, and the extracted preset type fields at least include: file operation information, process execution information, and network activity information. The application log stream is extracted using a parse tree, and the extracted template fields at least include: timestamp, process PID, and file identifier. Table 1 below is an example of the extraction of preset type fields.
[0040] Table 1
[0041]
[0042] Figure 2 is a flowchart for extracting template fields from the application log stream using a parse tree provided by an embodiment of the present invention. As Figure 2 shown, the input application log stream is transformed into a tokenized form, and a large number of structured fields or attributes are decomposed (for example, including 1-Log-Tokens, 2-Log-Tokens,...). Further parse tree generation is performed on the large number of structured fields or attributes, and the general structure of the log message is determined according to the parsing rules of the root node. To improve the parse tree traversal speed, saturated leaf nodes in the parse tree containing a large number of templates are split, transformed into internal nodes, and the corresponding templates are assigned to new leaf nodes to adjust the structure of the parse tree; here, to improve the template parsing efficiency, templates with highly similar content are merged based on the longest common subsequence, and redundant parts in the updated parse tree are removed to obtain an updated parse tree. Through the parse tree, the syntax and semantics of commands in the log stream are explicitly structured, upgrading security analysis from string matching to logical reasoning and significantly enhancing the ability to identify hidden threats.
[0043] After obtaining the respective fields corresponding to the system log stream and the application log stream, a system traceability graph G = <Subject, Object, Event> is generated by using multiple predefined type fields (such as file operation information, process execution information, and network activity information) and the interaction relationships between the multiple predefined type fields. Among them, both Subject and Object are predefined type fields. Subject represents the actor, that is, the entity that performs a certain operation, such as a process or a user; Object represents the object of the behavior, such as a file, a network connection, or another process; Event represents the edge of the system traceability graph, that is, the interaction relationship between the subject and the object, such as "read file", "write file", "create process", "establish network connection", etc.
[0044] Figure 3 is an example graph for generating the semantic traceability graph provided by the embodiments of the present invention. As Figure 3 shown, after obtaining the system traceability graph, according to the predefined association mapping rules, multiple template fields are associated with the system traceability graph to obtain the semantic traceability graph, which specifically includes: traversing multiple predefined type fields and multiple template fields, and screening out the common fields between the two; based on the common fields, associating the corresponding template fields in the multiple template fields with the vertex and edge information of the system traceability graph; expanding the template fields other than the common fields in the multiple template fields into new vertices and new edge information of the system traceability graph to obtain the semantic traceability graph SPG = <Subject c , Object c , Event c >.
[0045] Here, after obtaining the semantic traceability graph, since a large number of duplicate call logs are generated by a single user operation, there are many duplicate edges in the semantic traceability graph. In response to this situation, one approach is to analyze whether there is a causal dependency relationship between two duplicate events and delete the edges with duplicate events according to the analysis results; it should be understood that when deleting duplicate edges, the temporal precedence relationship needs to be considered; another approach is to set a time window to merge redundant edges according to the temporal precedence of the duplicate events, thereby further reducing the scale of the traceability graph and alleviating the problem of explosion of a large number of dependency relationships existing in the semantic traceability graph, and obtaining an optimized semantic traceability graph.
[0046] Here, the embedded vector database is obtained through the following steps: obtaining a data set mixed with multiple encrypted ransomware attack data and multiple benign software behavior data; using the data set to generate a retrieval semantic traceability graph; using a word vector model to convert the retrieval semantic traceability graph into multiple word embedding vectors; using a graph representation learning model based on the average aggregation method to process the multiple word embedding vectors to obtain multiple learning embedding vectors; storing the multiple learning embedding vectors to obtain the embedded vector database.
[0047] Exemplarily, using an existing encrypted ransomware attack dataset and a benign software behavior dataset, in the manner of extracting key fields from the above-mentioned system log stream and application log stream, multiple preset type fields and multiple template fields are obtained. Furthermore, a retrieval semantic traceability graph is generated using both of them, and then using the FastText embedding vector generation model, the retrieval semantic traceability graph is transformed into multiple word embedding vectors. Specifically, first traverse the comprehensive semantic traceability graph to generate a summary sentence for each vertex, where the events are sorted by timestamp to ensure the chronological order. The word vector model is used to generate an embedding vector Emb for each sub-word in the sentence. i , and the positional encoding vector PE is superimposed i , to obtain the embedding representation (C i = Emb i + PE i ). The embeddings of all sub-words are summed to obtain the final word embedding vector: After obtaining the word embedding vectors, a graph representation learning model in a semi-supervised manner is used to aggregate the features of neighbor nodes of the word embedding vectors in the local neighborhood to further improve the learning effect. At the same time, the cross-entropy loss function is used to control the learning process. By assigning different weights to different categories, the influence of the benign behavior category samples is effectively reduced, and the sensitivity of the model to attack behaviors is enhanced to obtain multiple learning embedding vectors.
[0048] In a possible implementation, the expression of the learning embedding vector corresponding to vertex v at the k + 1 layer satisfies:
[0049]
[0050] where σ is a non-linear activation function, W (k) is the existing learnable weight matrix in the graph representation learning model, used to map the aggregated features to a new embedding space, k ∈ 1,..., K, AGGREGATE k (·) is an aggregation function used to aggregate the embedding information of vertex v and the neighbor vertices in the k-th iteration, is the feature representation of neighbor vertex u in the k-th iteration, N(v) is the set of neighbors of vertex v in the optimized semantic traceability graph, and v is a positive integer.
[0051] Subsequently, multiple learned embedding vectors are stored in a database together with their neighbor information to avoid repeated calculations during the runtime phase for subsequent quick queries and use. In the database, each vertex of the semantic traceability graph has a corresponding hash table for storing the embedding vector of that vertex and its neighbor information. To ensure the standardized storage of key-value pairs, the unique identifier of a vertex is composed of certain attributes attached to it, which simplifies the expression while retaining discriminative semantic information. For example, for a vertex of network activity information, the source IP address and port attributes can be used as keys.
[0052] Here, the Adamic-Adar index is used to calculate the neighborhood similarity of the vertices in the semantic traceability graph. If the similarity between the neighborhood structure of a vertex and the neighborhood structure of the vertex stored in the database is greater than a threshold, they are considered to match; if it is less than the threshold, they are considered not to match. Furthermore, according to the matching result, the embedding vectors corresponding to the optimized semantic traceability graph are obtained, including: when the matching result is a match, obtaining the corresponding multiple learned embedding vectors in the embedding vector database as the embedding vectors corresponding to the optimized semantic traceability graph; when the matching result is a non-match, using a word vector model and a graph representation learning model based on the average aggregation method to convert the optimized semantic traceability graph into multiple embedding vectors to be retrieved.
[0053] It should be noted that the embedding vector database is obtained by calculating the semantic traceability graph based on the embedding vector algorithm, that is, the multiple embedding vectors in the embedding vector database can describe one or more semantic traceability graphs. If the optimized semantic traceability graph matches the embedding vectors in the embedding vector database, the already converted embedding vectors can be directly used for the next calculation, saving the step of converting the optimized semantic traceability graph into embedding vectors and improving the detection efficiency.
[0054] Here, after obtaining the embedding vectors corresponding to the optimized semantic traceability graph, this vector is input into a trained lightweight classification model for classification to obtain the corresponding deep detection result.
[0055] Step 130: In the case where the high-speed detection result indicates the existence of a ransomware attack behavior, stop all detections and trigger an alarm.
[0056] Exemplarily, when there is a ransomware attack behavior, an alarm is immediately triggered and the terminal protection tool is linked to block the process, and the firewall intercepts the external connection traffic. At the same time, the logs of user logins, file modifications, etc. are traced back to restore the attack chain. Finally, the rule threshold is optimized or the whitelist is expanded according to false alarm cases to form a closed-loop detection process.
[0057] Through Step 130, the detection efficiency can be quickly improved and the lag in attack detection can be avoided.
[0058] Step 140: In the case where no ransomware attack behavior is detected in the high-speed detection, continue with the in-depth detection to determine whether to trigger an alarm based on the in-depth detection results.
[0059] Here, if the in-depth detection result determines that a ransomware attack is detected, an early warning is immediately issued, a response is made, and the corresponding emergency response mechanism is triggered to reduce the impact of the attack. In addition, the detailed information of the attack behavior, including the attack source, propagation path, affected nodes, etc., will be automatically recorded for subsequent attack tracing and detailed analysis. At the same time, according to the attack characteristics detected in real time, the node embedding vectors in the graph will be continuously updated to enhance the prediction ability for future attacks.
[0060] Figure 4 It is an application example diagram of the ransomware attack rapid detection method based on the semantic traceability graph provided by the embodiments of the present invention. As Figure 4 shown, the entire detection method includes two parts: an offline stage and an online stage.
[0061] Offline stage: Use the malicious sample and benign sample datasets to construct multiple reduced semantic traceability graphs, and then input each semantic traceability graph into the FastText embedding vector generation model and the graph characterization model to be transformed into multiple learning embedding vectors and stored in the embedding vector database.
[0062] Online stage: Obtain the preprocessed mixed log stream, and synchronously perform high-speed detection and in-depth detection on it. The high-speed detection part includes malicious command matching and keyword blacklist detection. The in-depth detection part includes generating an optimized semantic traceability graph, matching the optimized semantic traceability graph with the embedding vectors in the embedding vector database. If there is a match, use the already transformed embedding vectors in the embedding vector database for the next classification and recognition. If there is no match, generate embedding vectors in real time for classification and recognition. Since the high-speed detection is faster, when a ransomware attack is detected in the high-speed detection result, all detections are stopped and an alarm is triggered; if no ransomware attack is detected, the in-depth detection continues.
[0063] Corresponding to a fast detection method for encrypted ransom attacks based on a semantic traceability graph provided by the present invention, an embodiment of the present invention further provides a fast detection system for encrypted ransom attacks based on a semantic traceability graph, which is used to implement the above-mentioned fast detection method for encrypted ransom attacks based on a semantic traceability graph; the fast detection system for encrypted ransom attacks includes: a data acquisition unit and a detection unit; the data acquisition unit is used to acquire a preprocessed mixed log stream; the detection unit is used to perform high-speed detection and in-depth detection on the preprocessed mixed log stream synchronously to obtain corresponding high-speed detection results and in-depth detection results; among them, the priority of the high-speed detection results is greater than the priority of the in-depth detection results; among them, the high-speed detection includes: malicious command matching and blacklist keyword detection; among them, the high-speed detection results are obtained by performing malicious command matching and blacklist keyword detection on the preprocessed mixed log stream; among them, the in-depth detection results are obtained by the following method: respectively extract semantic information related to encrypted ransom attack behaviors in the preprocessed mixed log stream to generate an optimized semantic traceability graph; based on a preset mapping rule, determine the matching result between the optimized semantic traceability graph and the embedded vector database; according to the matching result, obtain the embedded vector corresponding to the optimized semantic traceability graph; identify the embedded vector corresponding to the optimized semantic traceability graph to obtain in-depth detection results; the detection unit is further used to stop all detections and trigger an alarm when the high-speed detection result indicates the existence of encrypted ransom attack behaviors; the detection unit is further used to continue to perform in-depth detection when the high-speed detection result indicates the non-existence of encrypted ransom attack behaviors, so as to determine whether to trigger an alarm according to the in-depth detection results.
[0064] Moreover, the fast detection system for encrypted ransom attacks further includes: a semantic traceability graph generation unit; the semantic traceability graph generation unit is used to extract multiple preset type fields in the system log stream by using regular expressions; obtain multiple template fields in the application program log stream by using a parse tree; generate a system traceability graph based on the multiple preset type fields, where the multiple preset type fields are the vertices of the system traceability graph, and the interaction relationship between two adjacent preset type fields is used as the edge information of the system traceability graph; according to a predefined association mapping rule, associate the multiple template fields with the system traceability graph to obtain a semantic traceability graph; perform redundant edge pruning and duplicate edge merging on the semantic traceability graph to reduce the semantic traceability graph and obtain an optimized semantic traceability graph.
[0065] It should be understood that the execution manner of each unit in this system is exactly the same as the execution steps in the above-mentioned fast detection method for encrypted ransom attacks based on a semantic traceability graph. For the sake of brevity, it will not be elaborated here.
[0066] Aiming at the problems of high detection latency and low detection accuracy existing in the existing encryption ransomware attack detection methods, the present invention provides a fast detection method and system for encryption ransomware attacks based on a semantic traceability graph. This method deeply integrates real-time rule matching and semantic behavior correlation analysis through a task priority dynamic scheduling mechanism: First, based on the preprocessed hybrid log stream, high-speed detection (template-based rapid screening based on blacklist keywords and static features of malicious commands) and in-depth detection (construction of a semantic traceability graph and vectorized comparison, generating a deep threat graph by mining the behavior correlations among process chains, file operations, and network communications) are synchronously triggered; the combination of the two forms a hierarchical collaborative defense - when the high-speed detection engine identifies an encryption ransomware attack, it immediately intercepts and alarms, shortening the delay in handling critical threats. If the encryption ransomware attack is not identified, the in-depth detection continues, generating a semantic traceability graph for the preprocessed hybrid log stream to capture the encryption ransomware attack. Through the combined operation of moving the attack front forward and precisely deconstructing behaviors, while ensuring the real-time blocking effectiveness, the coverage of the semantic link of advanced threats is expanded, significantly optimizing the inherent contradiction of the traditional single detection mechanism among false alarm trade-off, computing power consumption, and the ability to capture hidden threats, realizing a leap in defense energy efficiency from discrete rule matching to high-order context reasoning, effectively improving the detection accuracy and reducing the detection latency.
[0067] The above content is a further detailed description of the present invention in combination with specific preferred implementation manners, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. A rapid detection method for encrypted ransom attacks based on a semantic traceability graph, characterized in that, Including: Obtain the preprocessed mixed log stream; Simultaneously perform high-speed detection and in-depth detection on the preprocessed mixed log stream to obtain corresponding high-speed detection results and in-depth detection results; In the case where the high-speed detection result indicates the existence of a crypto-ransomware attack behavior, stop all detections and trigger an alarm; In the case where the high-speed detection result indicates the non-existence of a crypto-ransomware attack behavior, continue to perform the in-depth detection to determine whether to trigger an alarm based on the in-depth detection result; Wherein, the high-speed detection result is obtained by performing malicious command matching and blacklist keyword detection on the preprocessed mixed log stream; Wherein, the in-depth detection result is obtained through the following method: Respectively extract the semantic information related to the crypto-ransomware attack behavior in the preprocessed mixed log stream to generate an optimized semantic traceability graph; based on a preset mapping rule, determine the matching result between the optimized semantic traceability graph and the embedded vector database; according to the matching result, obtain the embedded vector corresponding to the optimized semantic traceability graph; identify the embedded vector corresponding to the optimized semantic traceability graph to obtain the in-depth detection result.
2. The rapid detection method for encrypted ransomware attacks based on a semantic traceability graph according to claim 1, wherein The preprocessed mixed log stream includes: a system log stream and an application log stream; the respectively extracting the semantic information related to the crypto-ransomware attack behavior in the preprocessed mixed log stream to generate an optimized semantic traceability graph includes: Use regular expressions to extract multiple preset type fields in the system log stream; Use a parse tree to obtain multiple template fields in the application log stream; Based on the multiple preset type fields, generate a system traceability graph, wherein the multiple preset type fields are the vertices of the system traceability graph, and the interaction relationship between adjacent two preset type fields is used as the edge information of the system traceability graph; According to a predefined association mapping rule, associate the multiple template fields with the system traceability graph to obtain a semantic traceability graph; Perform redundant edge pruning and duplicate edge merging on the semantic traceability graph to reduce the semantic traceability graph to obtain the optimized semantic traceability graph.
3. The rapid detection method for encrypted ransomware attacks based on a semantic traceability graph according to claim 2, characterized in that, The according to a predefined association mapping rule, associating the multiple template fields with the system traceability graph to obtain a semantic traceability graph includes: Traverse the multiple preset type fields and the multiple template fields, and filter out the common fields between the two; Based on the common fields, associate the corresponding template fields in the multiple template fields with the vertices and edge information of the system traceability graph; Expand the template fields in the multiple template fields other than the common fields into new vertices and new edge information of the system traceability graph to obtain the semantic traceability graph.
4. The rapid detection method for encrypted ransomware attacks based on a semantic traceability graph according to claim 1, characterized in that, The embedded vector database is obtained through the following method: Obtain a data set mixed with multiple crypto-ransomware attack data and multiple benign software behavior data; Use the data set to generate a retrieval semantic traceability graph; Use a word vector model to convert the retrieval semantic traceability graph into multiple word embedding vectors; Use a graph representation learning model based on an average aggregation method to process the multiple word embedding vectors to obtain multiple learning embedding vectors; Store the multiple learned embedding vectors to obtain the embedding vector database.
5. The method for quickly detecting encrypted ransomware attacks based on a semantic traceability graph according to claim 4, wherein Obtaining the embedding vectors corresponding to the optimized semantic traceability graph according to the matching result includes: When the matching result is a match, obtain the corresponding multiple learned embedding vectors in the embedding vector database as the embedding vectors corresponding to the optimized semantic traceability graph; When the matching result is a mismatch, use a word vector model and a graph representation learning model based on an average aggregation method to convert the optimized semantic traceability graph into multiple embedding vectors to be retrieved.
6. The rapid detection method for encrypted ransomware attacks based on a semantic traceability graph according to claim 4, characterized in that The corresponding learned embedding vector of vertex v at the (k + 1)-th layer The expression satisfies: where, σ is a non-linear activation function, W (k) is a learnable weight matrix existing in the graph representation learning model, used to map the aggregated features to a new embedding space, k ∈ 1, ..., K, AGGREGATE k (·) is an aggregation function, used to aggregate the embedding information of vertex v and the neighbor vertices in the k-th iteration, is the feature representation of neighbor vertex u in the k-th iteration, N(v) is the set of neighbors of vertex v in the optimized semantic traceability graph, and v is a positive integer.
7. The method for quickly detecting encrypted ransomware attacks based on a semantic traceability graph according to claim 1, characterized in that The preprocessing includes: deduplication processing, normalization processing, and outlier processing.
8. The method for rapid detection of encrypted ransomware attacks based on a semantic traceability graph according to claim 2, characterized in that, The preset type fields at least include: file operation information, process execution information, and network activity information.
9. A rapid detection system for encrypted ransom attacks based on a semantic traceability graph, characterized in that, The encrypted ransomware attack rapid detection system is used to implement the encrypted ransomware attack rapid detection method based on the semantic traceability graph according to any one of claims 1 to 8 above; the encrypted ransomware attack rapid detection system includes: a data acquisition unit and a detection unit; The data acquisition unit is used to acquire the preprocessed mixed log stream; The detection unit is used to perform high-speed detection and in-depth detection on the preprocessed mixed log stream synchronously to obtain corresponding high-speed detection results and in-depth detection results; The detection unit is further used to stop all detections and trigger an alarm when the high-speed detection result indicates the existence of an encrypted ransomware attack behavior; The detection unit is further used to continue to perform the in-depth detection when the high-speed detection result indicates the non-existence of an encrypted ransomware attack behavior, so as to determine whether to trigger an alarm according to the in-depth detection result Among them, the high-speed detection result is obtained by performing malicious command matching and blacklist keyword detection on the preprocessed mixed log stream; Among them, the in-depth detection result is obtained through the following method: Extract the semantic information related to the encrypted ransomware attack behavior in the preprocessed mixed log stream respectively to generate an optimized semantic traceability graph; determine the matching result between the optimized semantic traceability graph and the embedding vector database based on a preset mapping rule; obtain the embedding vectors corresponding to the optimized semantic traceability graph according to the matching result; identify the embedding vectors corresponding to the optimized semantic traceability graph to obtain the in-depth detection result.
10. The rapid detection system for encrypted ransomware attacks based on a semantic traceability graph according to claim 9, wherein, The preprocessed mixed log stream includes: a system log stream and an application log stream; the encrypted ransomware attack rapid detection system further includes: a semantic traceability graph generation unit; The semantic traceability graph generation unit is configured to extract multiple preset type fields from the system log stream by using regular expressions; obtain multiple template fields from the application program log stream by using a parse tree; generate a system traceability graph based on the multiple preset type fields, where the multiple preset type fields are vertices of the system traceability graph, and the interaction relationship between two adjacent preset type fields is used as the edge information of the system traceability graph; associate the multiple template fields with the system traceability graph according to a predefined association mapping rule to obtain a semantic traceability graph; perform redundant edge pruning and duplicate edge merging on the semantic traceability graph to reduce the semantic traceability graph and obtain the optimized semantic traceability graph.
Citation Information
Cited By
Traceability detection method and device for network security event, and electronic equipment
CN122316758A
Cybersecurity event tracing detection method and device, and electronic device
CN122316758B