Real-time updating system and method for threat modeling elements
By constructing a sequence of monitoring parameters in the same dimension, calculating the change coefficients and generating trusted threat elements, the problem of low accuracy of update of threat modeling elements is solved, and the synchronous identification of threat model and attack situation is achieved.
Patent Information
- Application Number
- CN202510990400.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2045-07-18
AI Technical Summary
In the prior art, the update accuracy of threat modeling elements is low and cannot be synchronized with the current threat attack situation, resulting in low accuracy of threat model identification.
By constructing a sequence of monitoring parameters in the same dimension, calculating the change coefficient, generating initial threat elements and calculating credibility, filtering out trustworthiness threat elements, generating update instructions based on the comprehensive sorting value, and improving the recognition accuracy of the threat model.
The accuracy of threat factor updates and the accuracy of threat model identification are improved to ensure that the threat model is synchronized with the current threat attack situation.
Smart Images

Figure CN120509043A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of threat factor updating, and in particular to a real-time updating system and method for threat modeling elements. Background Art
[0002] A real-time update system for threat modeling elements is a key technology in the field of network security for responding to dynamic threat environments. In security development, threat modeling is usually defined in the requirements analysis and design phases. By establishing a feasible checklist and security baseline, risks are identified and managed in all aspects of the system. Updating threat modeling elements is one of the important means to ensure the accuracy of threat model identification.
[0003] In the existing technology, alarm information is usually regarded as a threat factor and the threat model is updated, but whether the alarm information has an impact or attack on the system is not evaluated, resulting in low accuracy in updating threat factors and low recognition accuracy of the threat model, and it cannot be guaranteed that the threat model is synchronized with the current threat attack situation. Summary of the Invention
[0004] To solve the above technical problems, the present application provides a real-time update system and method for threat modeling elements. By constructing several monitoring parameter sequences of the same dimension and calculating the variation coefficient, several initial threat elements are generated according to the variation coefficient, the credibility of each initial threat element is calculated, the credible threat element is determined according to the credibility and an updated threat element sequence is constructed, and update instructions are generated according to the updated threat element sequence, thereby improving the accuracy of the updated threat elements and the recognition accuracy of the threat model, and ensuring that the threat model is synchronized with the current threat attack situation.
[0005] In some embodiments of the present application, a real-time update system for threat modeling elements is provided, including: The monitoring module is used to set several monitoring points, obtain the monitoring parameters of each monitoring point in real time and perform cluster analysis to obtain several monitoring parameter sequences of the same dimension in the current monitoring period, and calculate the coefficient of change of each monitoring parameter sequence of the same dimension; An extraction module is used to extract a sequence of monitoring parameters of the same dimension whose variation coefficient is greater than a preset variation coefficient, generate a number of initial threat factors, and calculate the credibility of each initial threat factor; The screening module is used to screen out credible threat factors, evaluate the impact evaluation value of each credible threat factor, and generate a comprehensive ranking value based on the impact evaluation value and the change characteristics of the corresponding credible threat factor; The update module is used to sort a number of credible threat factors according to the comprehensive ranking value to obtain an updated threat factor sequence, and generate an update instruction based on the updated threat factor sequence.
[0006] In some embodiments of the present application, calculating the coefficient of variation of each same-dimensional monitoring parameter sequence includes: Determine a first monitoring parameter in each monitoring parameter sequence of the same dimension, and calculate a first monitoring parameter difference between the remaining monitoring parameters in the same monitoring parameter sequence of the same dimension and the first monitoring parameter; Generating a first parameter difference sequence corresponding to a monitoring parameter sequence of the same dimension according to a plurality of first monitoring parameter differences; Generate several parameter difference sequences for each monitoring parameter sequence of the same dimension in sequence; Traversing and preprocessing multiple parameter difference sequences of the same and same-dimensional monitoring parameter sequence, wherein the preprocessing includes deleting duplicate data and deleting erroneous data; Determining, based on the preprocessed parameter difference sequences, a mutation time node and a mutation feature at the corresponding mutation time node in each parameter difference sequence, and performing a first labeling, as well as a continuous change time interval and a continuous change feature in the corresponding continuous change time interval, and performing a second labeling; Comparing the first marks of several parameter difference sequences of the same and same-dimensional monitoring parameter sequence to obtain a first mark probability; The mutation time node and the corresponding mutation feature corresponding to the first mark whose first mark probability is greater than the preset first mark probability are set as a mutation factor; Comparing the second labels of several parameter difference sequences of the same and same-dimensional monitoring parameter sequence to obtain a second label probability; Performing a time comparison analysis on the continuous change time intervals corresponding to the second marks whose second mark probability is greater than the preset second mark probability, and determining a final continuous change time interval based on the analysis result; The final continuous change time interval and the corresponding continuous change feature are set as a continuous change factor; A number of mutation factors and a number of continuous change factors in a same-dimensional monitoring parameter sequence are determined, and a change coefficient of the corresponding same-dimensional monitoring parameter sequence is generated.
[0007] In some embodiments of the present application, calculating the coefficient of variation of each same-dimensional monitoring parameter sequence further includes: Generate corresponding mutation factor coefficients according to the mutation characteristics of each mutation factor in the monitoring parameter sequence of the same dimension; Generate corresponding continuous change factor coefficients according to the continuous change time interval length of each continuous change factor in the same-dimensional monitoring parameter sequence and the corresponding continuous change characteristics; Generate the variation coefficient of the corresponding monitoring parameter sequence of the same dimension according to multiple mutation factor coefficients and multiple continuous variation factor coefficients; The calculation formula of the coefficient of variation is: ; Where B is the coefficient of variation, is the coefficient of the i1th mutation factor, is the preset mutation factor coefficient, n1 is the number of mutation factors of the monitoring parameter sequence of the same dimension, and n2 is the number of continuous change factors of the monitoring parameter sequence of the same dimension. is the i2th continuously changing factor coefficient, a1 is the first weight coefficient, and a2 is the second weight coefficient.
[0008] In some embodiments of the present application, generating a number of initial threat factors and calculating the credibility of each initial threat factor include: Extracting a same-dimensional monitoring parameter sequence whose variation coefficient is greater than a preset variation coefficient, and extracting a number of mutation factors and a number of continuous variation factors corresponding to the same-dimensional monitoring parameter sequence in the current monitoring period; Each mutation factor and each continuous change factor of the corresponding monitoring parameter of the extracted monitoring parameter sequence of the same dimension are regarded as an initial threat factor; Generate several initial threat factors in the current monitoring period in sequence; Construct a topological map of monitoring points, mark several initial threat elements on the corresponding monitoring points, and generate several undetermined threat paths for each initial threat element based on the attack correlation information of the monitoring points and the time correlation information between the initial threat elements. Perform similarity analysis on the initial threat factors of each monitoring point and the preset threat factors in the threat factor reference library of the corresponding monitoring point to obtain the similarity; If the maximum similarity is less than the preset similarity threshold, the corresponding initial threat factor is directly eliminated; If there is a similarity greater than a preset similarity threshold, extracting a preset threat feature mapped to the corresponding preset threat element, wherein the preset threat feature includes a plurality of preset attack types, and each preset attack type is mapped to a corresponding attack probability; Each preset attack type includes several preset attack paths, each preset attack path includes several preset attack points, and each preset attack point is mapped to a corresponding preset attack behavior; Generating a number of preset threat paths corresponding to the initial threat elements according to the extracted preset threat features; The several pending threat paths of each initial threat factor are compared with the corresponding several preset threat paths, and the credibility of the corresponding initial threat factor is calculated based on the comparison results.
[0009] In some embodiments of the present application, generating a plurality of initial threat factors and calculating the credibility of each initial threat factor further includes: Taking each initial threat factor as a dividing node, the several pending threat paths of each initial threat factor are divided into a pre-pending threat path and a post-pending threat path; Taking each initial threat factor as a division node, the preset threat paths of each initial threat factor are divided into a front preset threat path and a rear preset threat path; Comparing each previous undetermined threat path with each previous preset threat path to obtain a previous path node coefficient and a previous node element coefficient, and generating a previous path coefficient based on the previous path node coefficient and the previous node element coefficient; If the previous path coefficients of the pending threat path and each previous preset threat path are both less than the preset path coefficient threshold, the current pending threat path and the corresponding subsequent pending threat path are eliminated; If there is a front path coefficient greater than the preset front path coefficient threshold, the subsequent pending threat path corresponding to the front path coefficient and the subsequent preset threat path corresponding to the previous preset threat path are screened out and compared to obtain the subsequent path node coefficient and the subsequent node element coefficient; Generate posterior path coefficients according to posterior path node coefficients and posterior node element coefficients; If the posterior path coefficient is greater than the preset posterior path coefficient threshold, the corresponding pending threat path is set as a credible threat path; The credibility of the corresponding initial threat factor is generated according to the number of credible threat paths and the corresponding preset attack probability.
[0010] In some embodiments of the present application, the calculation formula for the credibility of the initial threat factor is: ; Among them, K is the credibility, m1 is the number of credible threat paths, m0 is the number of preset threat paths, gs is the preset attack probability of the sth credible threat path, k1s is the front path coefficient of the sth credible threat path, is the preset threshold of the front path coefficient, q1 is the weight coefficient of the front path coefficient, k2s is the back path coefficient of the sth credible threat path, q2 is the weight coefficient of the back path coefficient, is the preset path coefficient threshold.
[0011] In some embodiments of the present application, screening out credible threat elements includes: Pre-set credibility threshold; If the credibility is greater than the credibility threshold, the initial threat factor is set as a credible threat factor; If the credibility is less than the credibility threshold, the initial threat factor is set as an untrustworthy threat factor.
[0012] In some embodiments of the present application, a comprehensive ranking value is generated based on the impact evaluation value and the change characteristics of the corresponding credible threat element, including: Based on several credible threat paths of each credible threat element and the corresponding preset attack types, predict the attack impact parameters of each credible threat path; Pre-set several attack evaluation indicators; Generate sub-attack evaluation values of several attack evaluation indicators based on the attack impact parameters of each credible threat path, and generate the attack evaluation value of the corresponding credible threat path by combining the weight coefficients of the corresponding attack evaluation indicators; Generate an impact evaluation value of the corresponding credible threat element based on the attack evaluation values of several credible threat paths of the same credible threat element and the preset attack probability of the corresponding credible threat path; Generate compensation coefficients based on the changing characteristics of credible threat factors; Generate a comprehensive ranking value based on the compensation coefficient and impact evaluation value.
[0013] In some embodiments of the present application, generating an update instruction for a threat modeling element based on an update threat element sequence includes: Sorting a number of credible threat factors according to the comprehensive ranking value of each credible threat factor in the current monitoring period to obtain an updated threat factor sequence; Perform correlation analysis on each credible threat factor in the updated threat factor sequence and the threat factor to be updated in the threat model to obtain a set of associated threat factors for each credible threat factor; Perform conflict analysis on each credible threat factor and the threat factor to be updated in the corresponding associated threat factor set. If a conflict exists, determine the conflict characteristics. Analyze conflict characteristics based on conflict evaluation indicators, generate a comprehensive conflict evaluation value based on the analysis results, select the corresponding conflict decision based on the comprehensive conflict evaluation value, and conduct conflict management until there is no conflict; If there is no conflict, an update instruction is generated according to the arrangement order of the credible threat elements in the update threat element sequence and the update cycle of the threat model.
[0014] In some embodiments of the present application, a real-time update method of threat modeling elements is also included: Set up several monitoring points, obtain the monitoring parameters of each monitoring point in real time and perform cluster analysis to obtain several monitoring parameter sequences of the same dimension in the current monitoring period, and calculate the coefficient of change of each monitoring parameter sequence of the same dimension; Extracting a same-dimensional monitoring parameter sequence with a variation coefficient greater than a preset variation coefficient, generating several initial threat factors, and calculating the credibility of each initial threat factor; Screen out credible threat factors, evaluate the impact of each credible threat factor, and generate a comprehensive ranking value based on the impact evaluation value and the change characteristics of the corresponding credible threat factor; Several credible threat factors are sorted according to the comprehensive sorting value to obtain an updated threat factor sequence, and an update instruction is generated based on the updated threat factor sequence.
[0015] Compared with the prior art, the real-time update system and method of threat modeling elements in the embodiments of the present application have the following advantages: By constructing several monitoring parameter sequences of the same dimension and calculating the variation coefficient, several initial threat factors are generated according to the variation coefficient, the credibility of each initial threat factor is calculated, the credible threat factors are determined according to the credibility and an updated threat factor sequence is constructed, and update instructions are generated according to the updated threat factor sequence. This improves the accuracy of the updated threat factors and the recognition accuracy of the threat model, ensuring that the threat model is synchronized with the current threat attack situation. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a schematic diagram of a real-time update system for threat modeling elements in an embodiment of the present application; Figure 2 It is a flowchart of a real-time update method of threat modeling elements in an embodiment of the present application. DETAILED DESCRIPTION
[0017] The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0018] In the description of this application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on this application.
[0019] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature specified as "first" or "second" may explicitly or implicitly include one or more of such features. Throughout this application, unless otherwise specified, "plurality" means two or more.
[0020] In the description of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in this application based on the specific circumstances.
[0021] like Figure 1 As shown, a real-time update system for threat modeling elements in an embodiment of the present application includes: The monitoring module is used to set several monitoring points, obtain the monitoring parameters of each monitoring point in real time and perform cluster analysis to obtain several monitoring parameter sequences of the same dimension in the current monitoring period, and calculate the coefficient of change of each monitoring parameter sequence of the same dimension; An extraction module is used to extract a sequence of monitoring parameters of the same dimension whose variation coefficient is greater than a preset variation coefficient, generate a number of initial threat factors, and calculate the credibility of each initial threat factor; The screening module is used to screen out credible threat factors, evaluate the impact evaluation value of each credible threat factor, and generate a comprehensive ranking value based on the impact evaluation value and the change characteristics of the corresponding credible threat factor; The update module is used to sort a number of credible threat factors according to the comprehensive ranking value to obtain an updated threat factor sequence, and generate an update instruction based on the updated threat factor sequence.
[0022] In this embodiment, monitoring points are set according to the key nodes of the coverage network. Real-time acquisition of monitoring parameters of each monitoring point refers to the detection and identification of network space infrastructure such as host operating systems, business applications, database systems, security equipment, audit equipment, terminals, and routing equipment, and the extraction of monitoring parameters such as connectivity coverage, performance capacity, and terminal characteristics.
[0023] In this embodiment, the same-dimensional monitoring parameter sequence refers to monitoring parameters of the same type at the same monitoring point constructed according to the time sequence in the monitoring period.
[0024] In some embodiments of the present application, calculating the coefficient of variation of each same-dimensional monitoring parameter sequence includes: Determine a first monitoring parameter in each monitoring parameter sequence of the same dimension, and calculate a first monitoring parameter difference between the remaining monitoring parameters in the same monitoring parameter sequence of the same dimension and the first monitoring parameter; Generating a first parameter difference sequence corresponding to a monitoring parameter sequence of the same dimension according to a plurality of first monitoring parameter differences; Generate several parameter difference sequences for each monitoring parameter sequence of the same dimension in sequence; Traversing and preprocessing multiple parameter difference sequences of the same and same-dimensional monitoring parameter sequence, wherein the preprocessing includes deleting duplicate data and deleting erroneous data; Determining, based on the preprocessed parameter difference sequences, a mutation time node and a mutation feature at the corresponding mutation time node in each parameter difference sequence, and performing a first labeling, as well as a continuous change time interval and a continuous change feature in the corresponding continuous change time interval, and performing a second labeling; Comparing the first marks of several parameter difference sequences of the same and same-dimensional monitoring parameter sequence to obtain a first mark probability; The mutation time node and the corresponding mutation feature corresponding to the first mark whose first mark probability is greater than the preset first mark probability are set as a mutation factor; Comparing the second labels of several parameter difference sequences of the same and same-dimensional monitoring parameter sequence to obtain a second label probability; Performing a time comparison analysis on the continuous change time intervals corresponding to the second marks whose second mark probability is greater than the preset second mark probability, and determining a final continuous change time interval based on the analysis result; The final continuous change time interval and the corresponding continuous change feature are set as a continuous change factor; A number of mutation factors and a number of continuous change factors in a same-dimensional monitoring parameter sequence are determined, and a change coefficient of the corresponding same-dimensional monitoring parameter sequence is generated.
[0025] In this embodiment, the first label probability refers to the frequency of occurrence of several parameter difference sequences of the same first label in the same dimension monitoring parameter sequence. The greater the frequency of occurrence, the greater the first label probability, that is, the higher the monitoring accuracy of the corresponding mutation time node and the corresponding mutation parameter value, which lays the foundation for the subsequent calculation of the variation coefficient.
[0026] In this embodiment, the second marking probability refers to the degree of overlap of the continuous change time interval of the same second mark in the time intervals of several parameter difference sequences of the same dimensional monitoring parameter sequence. The greater the degree of overlap of the time intervals, the greater the second marking probability, and the overlapping part of the time interval is used as the subsequent continuous change time interval, and the subsequent continuous change time interval is subjected to time comparison analysis. If there is the same time node, the corresponding continuous change time intervals are merged to obtain the final continuous change time interval.
[0027] In this embodiment, the mutation feature includes the mutation parameter value and the mutation rate, and the continuous change feature includes the continuous change parameter value, the continuous change rate, and the continuous change trend in the continuous change time interval.
[0028] In this embodiment, by screening out the mutation factor and continuous change factor of each same-dimensional monitoring parameter sequence, and combining the corresponding mutation parameter values and continuous change parameter values, the change coefficient of the corresponding same-dimensional monitoring parameter sequence is calculated. Based on the change coefficient, it is accurately evaluated whether the corresponding monitoring parameter has undergone significant changes and analyzed whether there are threat factors, laying the foundation for subsequent updating of threat modeling factors and ensuring update efficiency and accuracy.
[0029] In some embodiments of the present application, calculating the coefficient of variation of each same-dimensional monitoring parameter sequence further includes: Generate corresponding mutation factor coefficients according to the mutation characteristics of each mutation factor in the monitoring parameter sequence of the same dimension; Generate corresponding continuous change factor coefficients according to the continuous change time interval length of each continuous change factor in the same-dimensional monitoring parameter sequence and the corresponding continuous change characteristics; Generate the variation coefficient of the corresponding monitoring parameter sequence of the same dimension according to multiple mutation factor coefficients and multiple continuous variation factor coefficients; The calculation formula of the coefficient of variation is: ; Where B is the coefficient of variation, is the coefficient of the i1th mutation factor, is the preset mutation factor coefficient, n1 is the number of mutation factors of the monitoring parameter sequence of the same dimension, and n2 is the number of continuous change factors of the monitoring parameter sequence of the same dimension. is the i2th continuously changing factor coefficient, a1 is the first weight coefficient, and a2 is the second weight coefficient.
[0030] In this embodiment, the mutation parameter value, mutation rate, and mutation trend in the mutation feature are converted into numerical values of the same dimension as the mutation factor coefficient. When the mutation parameter value is larger and the mutation rate is faster, the corresponding mutation factor coefficient is larger, and vice versa.
[0031] In this embodiment, the continuously changing parameter value, continuously changing rate and continuously changing trend in the continuously changing time interval are converted into numerical values of the same dimension as the continuously changing factor coefficient. When the continuously changing time interval is longer, the continuously changing parameter value is larger, the continuously changing rate is faster and the continuously changing trend is continuously rising or falling, the corresponding continuously changing factor coefficient is larger, and vice versa.
[0032] In this embodiment, by calculating multiple mutation factor coefficients and multiple continuous change factor coefficients of the same-dimensional monitoring parameter sequence, the overall change of the corresponding monitoring parameters in the current monitoring period is accurately evaluated, and the corresponding change coefficient is obtained, which lays the foundation for the subsequent generation of initial threat factors and ensures the accuracy of the updated threat factors.
[0033] In some embodiments of the present application, generating a number of initial threat factors and calculating the credibility of each initial threat factor include: Extracting a same-dimensional monitoring parameter sequence whose variation coefficient is greater than a preset variation coefficient, and extracting a number of mutation factors and a number of continuous variation factors corresponding to the same-dimensional monitoring parameter sequence in the current monitoring period; Each mutation factor and each continuous change factor of the corresponding monitoring parameter of the extracted monitoring parameter sequence of the same dimension are regarded as an initial threat factor; Generate several initial threat factors in the current monitoring period in sequence; Construct a topological map of monitoring points, mark several initial threat elements on the corresponding monitoring points, and generate several undetermined threat paths for each initial threat element based on the attack correlation information of the monitoring points and the time correlation information between the initial threat elements. Perform similarity analysis on the initial threat factors of each monitoring point and the preset threat factors in the threat factor reference library of the corresponding monitoring point to obtain the similarity; If the maximum similarity is less than the preset similarity threshold, the corresponding initial threat factor is directly eliminated; If there is a similarity greater than a preset similarity threshold, extracting a preset threat feature mapped to the corresponding preset threat element, wherein the preset threat feature includes a plurality of preset attack types, and each preset attack type is mapped to a corresponding attack probability; Each preset attack type includes several preset attack paths, each preset attack path includes several preset attack points, and each preset attack point is mapped to a corresponding preset attack behavior; Generating a number of preset threat paths corresponding to the initial threat elements according to the extracted preset threat features; The several pending threat paths of each initial threat factor are compared with the corresponding several preset threat paths, and the credibility of the corresponding initial threat factor is calculated based on the comparison results.
[0034] In this embodiment, the pending threat path is based on the method of multi-dimensional correlation analysis and network analysis, which associates seemingly unrelated monitoring points and corresponding initial threat factors to obtain the possible threat attack path of each initial threat factor. Specifically, it is set based on the attack correlation information between monitoring points and the change time nodes of the initial threat factors between different monitoring points.
[0035] In this embodiment, a plurality of preset threat paths are set based on preset attack paths corresponding to preset threat features having a similarity greater than a preset similarity threshold. The preset attack paths refer to historical threat attack paths generated when corresponding initial threat elements appear.
[0036] In this embodiment, the preset threat path and the pending threat path are compared to obtain a comparison result of the path nodes and node behaviors of the pending threat path and the preset threat path, thereby judging whether the pending threat path is feasible, and combining the corresponding preset attack probability to generate the credibility of the corresponding initial threat factor, laying the foundation for the subsequent construction and update of the threat factor, ensuring the accuracy of the threat factor, and improving the update accuracy and efficiency.
[0037] In some embodiments of the present application, generating a plurality of initial threat factors and calculating the credibility of each initial threat factor further includes: Taking each initial threat factor as a dividing node, the several pending threat paths of each initial threat factor are divided into a pre-pending threat path and a post-pending threat path; Taking each initial threat factor as a division node, the preset threat paths of each initial threat factor are divided into a front preset threat path and a rear preset threat path; Comparing each previous undetermined threat path with each previous preset threat path to obtain a previous path node coefficient and a previous node element coefficient, and generating a previous path coefficient based on the previous path node coefficient and the previous node element coefficient; If the previous path coefficients of the pending threat path and each previous preset threat path are both less than the preset path coefficient threshold, the current pending threat path and the corresponding subsequent pending threat path are eliminated; If there is a front path coefficient greater than the preset front path coefficient threshold, the subsequent pending threat path corresponding to the front path coefficient and the subsequent preset threat path corresponding to the previous preset threat path are screened out and compared to obtain the subsequent path node coefficient and the subsequent node element coefficient; Generate posterior path coefficients according to posterior path node coefficients and posterior node element coefficients; If the posterior path coefficient is greater than the preset posterior path coefficient threshold, the corresponding pending threat path is set as a credible threat path; The credibility of the corresponding initial threat factor is generated according to the number of credible threat paths and the corresponding preset attack probability.
[0038] In this embodiment, the front path node coefficient refers to the degree of consistency between the number of monitoring points involved in the previous pending threat path and the previous preset threat path and the order of the monitoring points. The greater the degree of consistency, the larger the corresponding front path node coefficient, and vice versa. The front node element coefficient refers to the degree of consistency between the monitoring parameters and changing characteristics of the initial threat elements at the monitoring points involved in the previous pending threat path and the previous preset threat path and the preset attack behavior at the corresponding preset attack points. The greater the degree of consistency, the larger the corresponding front node element coefficient, and vice versa. The same applies to the rear path node coefficient and the rear node element coefficient, and they will not be repeated here.
[0039] In this embodiment, by dividing the pending threat path and the preset threat path into a front pending threat path, a front preset threat path, a rear pending threat path, and a rear preset threat path, and calculating the front path coefficient and the rear path coefficient, a credible threat path is obtained. The credibility of the corresponding initial threat factor is calculated based on the credible threat path, laying the foundation for the subsequent construction of the updated threat factor and improving the update accuracy.
[0040] In some embodiments of the present application, the calculation formula for the credibility of the initial threat factor is: ; Among them, K is the credibility, m1 is the number of credible threat paths, m0 is the number of preset threat paths, gs is the preset attack probability of the sth credible threat path, k1s is the front path coefficient of the sth credible threat path, is the preset threshold of the front path coefficient, q1 is the weight coefficient of the front path coefficient, k2s is the back path coefficient of the sth credible threat path, q2 is the weight coefficient of the back path coefficient, is the preset path coefficient threshold.
[0041] In this embodiment, q1=0.7, q2=0.3.
[0042] In this embodiment, the credibility of the corresponding initial threat factor is calculated by calculating the front path coefficient and the back path coefficient of each credible threat path. The front path coefficient is the main factor for evaluating the initial threat factor, and the back path coefficient is the secondary factor for evaluating the initial threat factor.
[0043] In this embodiment, the credible threat path is determined by the front path coefficient and the back path information, and the credibility of the corresponding initial threat factor is evaluated according to the number of credible threat paths of each initial threat factor and the preset attack probability. This improves the accuracy of the updated threat factor, reduces the error rate of the threat factor update, and ensures that the threat model is synchronized with the current threat attack situation.
[0044] In some embodiments of the present application, screening out credible threat elements includes: Pre-set credibility threshold; If the credibility is greater than the credibility threshold, the initial threat factor is set as a credible threat factor; If the credibility is less than the credibility threshold, the initial threat factor is set as an untrustworthy threat factor.
[0045] In some embodiments of the present application, a comprehensive ranking value is generated based on the impact evaluation value and the change characteristics of the corresponding credible threat element, including: Based on several credible threat paths of each credible threat element and the corresponding preset attack types, predict the attack impact parameters of each credible threat path; Pre-set several attack evaluation indicators; Generate sub-attack evaluation values of several attack evaluation indicators based on the attack impact parameters of each credible threat path, and generate the attack evaluation value of the corresponding credible threat path by combining the weight coefficients of the corresponding attack evaluation indicators; Generate an impact evaluation value of the corresponding credible threat element based on the attack evaluation values of several credible threat paths of the same credible threat element and the preset attack probability of the corresponding credible threat path; Generate compensation coefficients based on the changing characteristics of credible threat factors; Generate a comprehensive ranking value based on the compensation coefficient and impact evaluation value.
[0046] In this embodiment, the attack evaluation indicators include but are not limited to the degree of impact after a successful attack, the importance of the attack point, the attack type, the attack range, etc. When the degree of impact, the importance, and the attack range are greater, the corresponding sub-attack evaluation value is greater, that is, the attack evaluation value is greater, and vice versa. When the attack evaluation value is greater and the preset attack probability is greater, the corresponding impact evaluation value is greater, and vice versa.
[0047] In this embodiment, when the credible threat factor is a mutation factor, the change characteristics are the mutation rate and the mutation value. The change characteristics of the mutation factor are analyzed for similarity with the change characteristics of other mutation factors with the same monitoring parameters at the same monitoring point. The mutation time interval of the current credible threat factor is determined based on the similarity analysis results, and a compensation coefficient is set based on the mutation time interval. The smaller the mutation time interval, the larger the compensation coefficient, and vice versa.
[0048] In this embodiment, when the credible threat factor is a continuously changing factor, the change characteristics are the continuously changing parameter value, the continuously changing rate, and the continuously changing trend. The change characteristics of the continuously changing factor are analyzed similarly to the change characteristics of other continuously changing factors of the same monitoring parameter at the same monitoring point to determine the continuous change time interval of the current credible threat factor. The smaller the continuous change time interval, the larger the compensation coefficient, and vice versa.
[0049] In this embodiment, a comprehensive ranking value is generated by the impact evaluation value and the compensation coefficient. When the impact evaluation value and the compensation coefficient are larger, the corresponding comprehensive ranking value is larger. The credible threat factors are sorted according to the size of the comprehensive ranking value, so that the credible threat factors with large impact evaluation values and fast updates are updated first, ensuring that the threat model is synchronized with the current threat attack situation.
[0050] In some embodiments of the present application, generating an update instruction for a threat modeling element based on an update threat element sequence includes: Sorting a number of credible threat factors according to the comprehensive ranking value of each credible threat factor in the current monitoring period to obtain an updated threat factor sequence; Perform correlation analysis on each credible threat factor in the updated threat factor sequence and the threat factor to be updated in the threat model to obtain a set of associated threat factors for each credible threat factor; Perform conflict analysis on each credible threat factor and the threat factor to be updated in the corresponding associated threat factor set. If a conflict exists, determine the conflict characteristics. Analyze conflict characteristics based on conflict evaluation indicators, generate a comprehensive conflict evaluation value based on the analysis results, select the corresponding conflict decision based on the comprehensive conflict evaluation value, and conduct conflict management until there is no conflict; If there is no conflict, an update instruction is generated according to the arrangement order of the credible threat elements in the update threat element sequence and the update cycle of the threat model.
[0051] In this embodiment, the conflict characteristics include the conflict type and the conflict cause. The conflict evaluation indicators include but are not limited to the scope of impact on the threat model, the degree of change to existing risks, the degree of impact on implemented security control policies, the degree of impact on business processes and key assets, potential compliance impacts, implementation costs, maintenance complexity, etc. When the scope of impact is smaller, the degree of change is smaller, the implementation cost is lower, and the maintenance complexity is lower, the comprehensive conflict evaluation value is smaller, and vice versa.
[0052] In this embodiment, when the comprehensive conflict evaluation value is in the first preset conflict evaluation value interval, the conflict decision is a minimum management decision, including but not limited to supplementing the security control of the current credible threat factor, updating the risk acceptance standard, adjusting the effectiveness score of the existing control strategy, etc. When the comprehensive conflict evaluation value is in the second preset conflict evaluation value interval, the conflict decision is a medium management decision, including but not limited to local remodeling of the affected components, converting different versions of credible threat factors, etc. When the comprehensive conflict evaluation value is in the third preset conflict evaluation value interval, the conflict decision is a maximum management decision, including but not limited to rebuilding the data flow diagram based on the new threat factor, establishing a transition mapping table between the new and old models, etc.
[0053] In this embodiment, by performing conflict analysis and management on the updated threat factor sequence, real-time updates are performed based on the order and update cycle of the updated threat factor sequence after management, thereby improving the accuracy and efficiency of threat factor updates and ensuring that the threat model is synchronized with the current threat attack situation.
[0054] In some embodiments of the present application, Figure 2 As shown, a real-time update method for threat modeling elements is also included: Step S201: Set a number of monitoring points, obtain the monitoring parameters of each monitoring point in real time and perform cluster analysis to obtain a number of monitoring parameter sequences of the same dimension in the current monitoring period, and calculate the coefficient of variation of each monitoring parameter sequence of the same dimension; Step S202: extracting a same-dimensional monitoring parameter sequence whose variation coefficient is greater than a preset variation coefficient, generating a number of initial threat factors, and calculating the credibility of each initial threat factor; Step S203: Screen out credible threat factors, evaluate the impact evaluation value of each credible threat factor, and generate a comprehensive ranking value based on the impact evaluation value and the change characteristics of the corresponding credible threat factor; Step S204: sorting a number of credible threat factors according to the comprehensive ranking value to obtain an updated threat factor sequence, and generating an update instruction based on the updated threat factor sequence.
[0055] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and replacements can be made without departing from the technical principles of the present application. These improvements and replacements should also be regarded as the scope of protection of the present application.
Claims
1. A real-time update system for threat modeling elements, characterized in that: include: The monitoring module is used to set several monitoring points, obtain the monitoring parameters of each monitoring point in real time and perform cluster analysis to obtain several monitoring parameter sequences of the same dimension in the current monitoring period, and calculate the coefficient of change of each monitoring parameter sequence of the same dimension; An extraction module is used to extract a sequence of monitoring parameters of the same dimension whose variation coefficient is greater than a preset variation coefficient, generate a number of initial threat factors, and calculate the credibility of each initial threat factor; The screening module is used to screen out credible threat factors, evaluate the impact evaluation value of each credible threat factor, and generate a comprehensive ranking value based on the impact evaluation value and the change characteristics of the corresponding credible threat factor; The update module is used to sort a number of credible threat factors according to the comprehensive ranking value to obtain an updated threat factor sequence, and generate an update instruction based on the updated threat factor sequence.
2. The real-time update system for threat modeling elements according to claim 1, wherein: Calculate the coefficient of variation of each monitoring parameter sequence of the same dimension, including: Determine a first monitoring parameter in each monitoring parameter sequence of the same dimension, and calculate a first monitoring parameter difference between the remaining monitoring parameters in the same monitoring parameter sequence of the same dimension and the first monitoring parameter; Generating a first parameter difference sequence corresponding to a monitoring parameter sequence of the same dimension according to a plurality of first monitoring parameter differences; Generate several parameter difference sequences for each monitoring parameter sequence of the same dimension in sequence; Traversing and preprocessing multiple parameter difference sequences of the same and same-dimensional monitoring parameter sequence, wherein the preprocessing includes deleting duplicate data and deleting erroneous data; Determining, based on the preprocessed parameter difference sequences, a mutation time node and a mutation feature at the corresponding mutation time node in each parameter difference sequence, and performing a first labeling, as well as a continuous change time interval and a continuous change feature in the corresponding continuous change time interval, and performing a second labeling; Comparing the first marks of several parameter difference sequences of the same and same-dimensional monitoring parameter sequence to obtain a first mark probability; The mutation time node and the corresponding mutation feature corresponding to the first mark whose first mark probability is greater than the preset first mark probability are set as a mutation factor; Comparing the second labels of several parameter difference sequences of the same and same-dimensional monitoring parameter sequence to obtain a second label probability; Performing a time comparison analysis on the continuous change time intervals corresponding to the second marks whose second mark probability is greater than the preset second mark probability, and determining a final continuous change time interval based on the analysis result; The final continuous change time interval and the corresponding continuous change feature are set as a continuous change factor; A number of mutation factors and a number of continuous change factors in a same-dimensional monitoring parameter sequence are determined, and a change coefficient of the corresponding same-dimensional monitoring parameter sequence is generated.
3. The real-time update system for threat modeling elements according to claim 2, wherein: Calculate the coefficient of variation of each monitoring parameter sequence of the same dimension, including: Generate corresponding mutation factor coefficients according to the mutation characteristics of each mutation factor in the monitoring parameter sequence of the same dimension; Generate corresponding continuous change factor coefficients according to the continuous change time interval length of each continuous change factor in the same-dimensional monitoring parameter sequence and the corresponding continuous change characteristics; Generate the variation coefficient of the corresponding monitoring parameter sequence of the same dimension according to multiple mutation factor coefficients and multiple continuous variation factor coefficients; The calculation formula of the coefficient of variation is: ; Where B is the coefficient of variation, is the coefficient of the i1th mutation factor, is the preset mutation factor coefficient, n1 is the number of mutation factors of the monitoring parameter sequence of the same dimension, and n2 is the number of continuous change factors of the monitoring parameter sequence of the same dimension. is the i2th continuously changing factor coefficient, a1 is the first weight coefficient, and a2 is the second weight coefficient.
4. The real-time update system for threat modeling elements according to claim 3, wherein: Generate several initial threat factors and calculate the credibility of each initial threat factor, including: Extracting a same-dimensional monitoring parameter sequence whose variation coefficient is greater than a preset variation coefficient, and extracting a number of mutation factors and a number of continuous variation factors corresponding to the same-dimensional monitoring parameter sequence in the current monitoring period; Each mutation factor and each continuous change factor of the corresponding monitoring parameter of the extracted monitoring parameter sequence of the same dimension are regarded as an initial threat factor; Generate several initial threat factors in the current monitoring period in sequence; Construct a topological map of monitoring points, mark several initial threat elements on the corresponding monitoring points, and generate several undetermined threat paths for each initial threat element based on the attack correlation information of the monitoring points and the time correlation information between the initial threat elements. Perform similarity analysis on the initial threat factors of each monitoring point and the preset threat factors in the threat factor reference library of the corresponding monitoring point to obtain the similarity; If the maximum similarity is less than the preset similarity threshold, the corresponding initial threat factor is directly eliminated; If there is a similarity greater than a preset similarity threshold, extracting a preset threat feature mapped to the corresponding preset threat element, wherein the preset threat feature includes a plurality of preset attack types, and each preset attack type is mapped to a corresponding attack probability; Each preset attack type includes several preset attack paths, each preset attack path includes several preset attack points, and each preset attack point is mapped to a corresponding preset attack behavior; Generating a number of preset threat paths corresponding to the initial threat elements according to the extracted preset threat features; The several pending threat paths of each initial threat factor are compared with the corresponding several preset threat paths, and the credibility of the corresponding initial threat factor is calculated based on the comparison results.
5. The real-time update system for threat modeling elements according to claim 4, wherein: Generate several initial threat factors, calculate the credibility of each initial threat factor, and also include: Taking each initial threat factor as a dividing node, the several pending threat paths of each initial threat factor are divided into a pre-pending threat path and a post-pending threat path; Taking each initial threat factor as a division node, the preset threat paths of each initial threat factor are divided into a front preset threat path and a rear preset threat path; Comparing each previous undetermined threat path with each previous preset threat path to obtain a previous path node coefficient and a previous node element coefficient, and generating a previous path coefficient based on the previous path node coefficient and the previous node element coefficient; If the previous path coefficients of the pending threat path and each previous preset threat path are both less than the preset path coefficient threshold, the current pending threat path and the corresponding subsequent pending threat path are eliminated; If there is a front path coefficient greater than the preset front path coefficient threshold, the subsequent pending threat path corresponding to the front path coefficient and the subsequent preset threat path corresponding to the previous preset threat path are screened out and compared to obtain the subsequent path node coefficient and the subsequent node element coefficient; Generate posterior path coefficients according to posterior path node coefficients and posterior node element coefficients; If the posterior path coefficient is greater than the preset posterior path coefficient threshold, the corresponding pending threat path is set as a credible threat path; The credibility of the corresponding initial threat factor is generated according to the number of credible threat paths and the corresponding preset attack probability.
6. The real-time update system for threat modeling elements according to claim 5, wherein: The calculation formula for the credibility of the initial threat factor is: ; Among them, K is the credibility, m1 is the number of credible threat paths, m0 is the number of preset threat paths, gs is the preset attack probability of the sth credible threat path, k1s is the front path coefficient of the sth credible threat path, is the preset threshold of the front path coefficient, q1 is the weight coefficient of the front path coefficient, k2s is the back path coefficient of the sth credible threat path, q2 is the weight coefficient of the back path coefficient, is the preset path coefficient threshold.
7. The real-time update system for threat modeling elements according to claim 6, wherein: Screen out credible threat elements, including: Pre-set credibility threshold; If the credibility is greater than the credibility threshold, the initial threat factor is set as a credible threat factor; If the credibility is less than the credibility threshold, the initial threat factor is set as an untrustworthy threat factor.
8. The real-time update system for threat modeling elements according to claim 7, wherein: A comprehensive ranking value is generated based on the impact assessment value and the change characteristics of the corresponding credible threat factors, including: Based on several credible threat paths of each credible threat element and the corresponding preset attack types, predict the attack impact parameters of each credible threat path; Pre-set several attack evaluation indicators; Generate sub-attack evaluation values of several attack evaluation indicators based on the attack impact parameters of each credible threat path, and generate the attack evaluation value of the corresponding credible threat path by combining the weight coefficients of the corresponding attack evaluation indicators; Generate an impact evaluation value of the corresponding credible threat element based on the attack evaluation values of several credible threat paths of the same credible threat element and the preset attack probability of the corresponding credible threat path; Generate compensation coefficients based on the changing characteristics of credible threat factors; Generate a comprehensive ranking value based on the compensation coefficient and impact evaluation value.
9. The real-time update system for threat modeling elements according to claim 8, wherein: Generate an update instruction for a threat modeling element based on the update threat element sequence, including: Sorting a number of credible threat factors according to the comprehensive ranking value of each credible threat factor in the current monitoring period to obtain an updated threat factor sequence; Perform correlation analysis on each credible threat factor in the updated threat factor sequence and the threat factor to be updated in the threat model to obtain a set of associated threat factors for each credible threat factor; Perform conflict analysis on each credible threat factor and the threat factor to be updated in the corresponding associated threat factor set. If a conflict exists, determine the conflict characteristics. Analyze conflict characteristics based on conflict evaluation indicators, generate a comprehensive conflict evaluation value based on the analysis results, select the corresponding conflict decision based on the comprehensive conflict evaluation value, and conduct conflict management until there is no conflict; If there is no conflict, an update instruction is generated according to the arrangement order of the credible threat elements in the update threat element sequence and the update cycle of the threat model.
10. A real-time update method for threat modeling elements, characterized in that: include: Set up several monitoring points, obtain the monitoring parameters of each monitoring point in real time and perform cluster analysis to obtain several monitoring parameter sequences of the same dimension in the current monitoring period, and calculate the coefficient of change of each monitoring parameter sequence of the same dimension; Extracting a same-dimensional monitoring parameter sequence with a variation coefficient greater than a preset variation coefficient, generating several initial threat factors, and calculating the credibility of each initial threat factor; Screen out credible threat factors, evaluate the impact of each credible threat factor, and generate a comprehensive ranking value based on the impact evaluation value and the change characteristics of the corresponding credible threat factor; Several credible threat factors are sorted according to the comprehensive sorting value to obtain an updated threat factor sequence, and an update instruction is generated based on the updated threat factor sequence.
Citation Information
Patent Citations
Intrusion threat index expansion method and device based on DNS analysis message and electronic equipment
CN110868379A
Threat attack protection decision-making method adopting AI and big data analysis and AI system
CN114866330A
Threat scoring method and device and electronic equipment
CN116015899A
Threat intelligence-based credibility updating method and apparatus, and electronic device
CN116170202A
Financial risk data management method based on machine learning
CN117726439A