A system and method for real-time updating of threat modeling elements
By constructing a sequence of monitoring parameters in the same dimension, calculating the change coefficients, and generating credible threat elements, the problem of low accuracy in updating threat modeling elements is solved, and the synchronization of threat models and attack posture is achieved.
Patent Information
- Application Number
- CN202510990400.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-07-18
AI Technical Summary
In existing technologies, the accuracy of updating threat modeling elements is low, resulting in the threat model being out of sync with the current threat attack situation, and making it impossible to effectively assess the impact of alarm information on the system.
By constructing a sequence of monitoring parameters in the same dimension, calculating the change coefficient, generating initial threat elements and calculating their credibility, filtering out credible threat elements, constructing an updated threat element sequence, and generating update instructions, accuracy and synchronization can be improved.
It improves the accuracy of threat model identification and the accuracy of updating threat elements, ensuring that the threat model is synchronized with the current threat attack situation.
Smart Images

Figure CN120509043B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of threat element updating, in particular to a real-time updating system and method of threat modeling elements. BACKGROUND
[0002] The real-time updating system of threat modeling elements is a key technology in the field of network security to cope with dynamic threat environment. In security development, threat modeling is usually defined in the requirement analysis and design phase. A check list and security baseline are established to identify and manage risks in each link of the system. Threat modeling element updating is one of the important means to ensure the accuracy of threat model identification.
[0003] In the prior art, the alarm information is usually taken as a threat element, and the threat model is updated. However, whether the alarm information has an impact on the system or an attack is not evaluated, resulting in low accuracy of updating threat elements and low identification accuracy of threat models, which cannot guarantee that the threat model is synchronized with the current threat attack situation. SUMMARY
[0004] To solve the above technical problems, the present application provides a real-time updating system and method of threat modeling elements. By constructing a plurality of same dimension monitoring parameter sequences and calculating the change coefficient, a plurality of initial threat elements are generated according to the change coefficient. The credibility of each initial threat element is calculated, and the credible threat elements are determined according to the credibility to construct an updated threat element sequence. The update instruction is generated according to the updated threat element sequence, which improves the accuracy of updating threat elements and the identification accuracy of threat models, and ensures that the threat model is synchronized with the current threat attack situation.
[0005] In some embodiments of the present application, a real-time updating system of threat modeling elements is provided, which comprises:
[0006] A monitoring module is configured to set a plurality of monitoring points, acquire monitoring parameters of each monitoring point in real time, and perform clustering analysis to obtain a plurality of same dimension monitoring parameter sequences in a current monitoring period, and calculate the change coefficient of each same dimension monitoring parameter sequence.
[0007] An extraction module is configured to extract same dimension monitoring parameter sequences with a change coefficient greater than a preset change coefficient, generate a plurality of initial threat elements, and calculate the credibility of each initial threat element.
[0008] A screening module is configured to screen credible threat elements, evaluate the impact evaluation value of each credible threat element, and generate a comprehensive ranking value according to the impact evaluation value and the change characteristics of the corresponding credible threat element.
[0009] An updating module is configured to sort the plurality of credible threat elements according to the comprehensive ranking values to obtain an updated threat element sequence, and generate an updating instruction based on the updated threat element sequence.
[0010] In some embodiments of the present application, a change coefficient of each same-dimension monitoring parameter sequence is calculated, including:
[0011] A first monitoring parameter in each same-dimension monitoring parameter sequence is determined, and a first monitoring parameter difference between the remaining monitoring parameters in the same-dimension monitoring parameter sequence and the first monitoring parameter is calculated;
[0012] A first parameter difference sequence of the corresponding same-dimension monitoring parameter sequence is generated according to the plurality of first monitoring parameter differences;
[0013] A plurality of parameter difference sequences of each same-dimension monitoring parameter sequence are sequentially generated;
[0014] The plurality of parameter difference sequences of the same-dimension monitoring parameter sequence are traversed and preprocessed, wherein the preprocessing includes deleting duplicate data and deleting error data;
[0015] According to the plurality of preprocessed parameter difference sequences, a mutation time node in each parameter difference sequence, a mutation feature at the corresponding mutation time node, a continuous change time interval, and a continuous change feature in the corresponding continuous change time interval are determined, and a first label and a second label are performed;
[0016] The first labels of the plurality of parameter difference sequences of the same-dimension monitoring parameter sequence are compared to obtain a first label probability;
[0017] The mutation time node and the corresponding mutation feature corresponding to the first label with a first label probability greater than a preset first label probability are set as a mutation factor;
[0018] The second labels of the plurality of parameter difference sequences of the same-dimension monitoring parameter sequence are compared to obtain a second label probability;
[0019] The continuous change time interval corresponding to the second label with a second label probability greater than a preset second label probability is subjected to time comparison analysis, and a final continuous change time interval is determined according to the analysis result;
[0020] The final continuous change time interval and the corresponding continuous change feature are set as a continuous change factor;
[0021] A plurality of mutation factors and a plurality of continuous change factors in the same-dimension monitoring parameter sequence are determined, and a change coefficient of the corresponding same-dimension monitoring parameter sequence is generated.
[0022] In some embodiments of the present application, the change coefficient of each same-dimension monitoring parameter sequence is calculated, and the change coefficient is further calculated by:
[0023] According to the mutation characteristics in each mutation factor in the same-dimension monitoring parameter sequence, a corresponding mutation factor coefficient is generated;
[0024] According to the continuous change time interval length and the corresponding continuous change characteristics of each continuous change factor in the same-dimension monitoring parameter sequence, a corresponding continuous change factor coefficient is generated;
[0025] According to the plurality of mutation factor coefficients and the plurality of continuous change factor coefficients, a change coefficient of the corresponding same-dimension monitoring parameter sequence is generated;
[0026] The calculation formula of the change coefficient is:
[0027] ;
[0028] Wherein, B is the change coefficient, is the ith mutation factor coefficient, is the preset mutation factor coefficient, n1 is the number of mutation factors of the same-dimension monitoring parameter sequence, n2 is the number of continuous change factors of the same-dimension monitoring parameter sequence, is the ith continuous change factor coefficient, a1 is the first weight coefficient, and a2 is the second weight coefficient.
[0029] In some embodiments of the present application, a plurality of initial threat elements are generated, and the credibility of each initial threat element is calculated, including:
[0030] The same-dimension monitoring parameter sequence with a change coefficient greater than a preset change coefficient is extracted, and a plurality of mutation factors and a plurality of continuous change factors corresponding to the same-dimension monitoring parameter sequence in the current monitoring period are extracted;
[0031] Each mutation factor and each continuous change factor of the extracted same-dimension monitoring parameter sequence corresponding to the monitoring parameter is regarded as an initial threat element;
[0032] A plurality of initial threat elements in the current monitoring period are generated in turn;
[0033] A monitoring point position topology graph is constructed, and a plurality of initial threat elements are marked on the corresponding monitoring point positions. Based on the attack association information of the monitoring point positions and the time association information between the initial threat elements, a plurality of pending threat paths of each initial threat element are generated;
[0034] The initial threat element of each monitoring point position is subjected to similarity analysis with the preset threat element in the threat element reference library corresponding to the monitoring point position, and a similarity degree is obtained;
[0035] If the maximum similarity is less than the preset similarity threshold, the corresponding initial threat element is directly eliminated;
[0036] If there is a similarity greater than the preset similarity threshold, a preset threat feature mapped by the corresponding preset threat element is extracted, the preset threat feature includes a plurality of preset attack types, and each preset attack type is mapped with a corresponding attack probability;
[0037] Each preset attack type includes a plurality of preset attack paths, each preset attack path includes a plurality of preset attack points, and each preset attack point is mapped with a corresponding preset attack behavior.
[0038] According to the extracted preset threat feature, a plurality of preset threat paths of the corresponding initial threat element are generated;
[0039] Compare the plurality of undetermined threat paths of each initial threat element with the corresponding plurality of preset threat paths, and calculate the credibility of the corresponding initial threat element according to the comparison result.
[0040] In some embodiments of the present application, a plurality of initial threat elements are generated, and the credibility of each initial threat element is calculated, which further includes:
[0041] Each initial threat element is taken as a division node, and the plurality of undetermined threat paths of each initial threat element are divided into front undetermined threat paths and rear undetermined threat paths;
[0042] Each initial threat element is taken as a division node, and the plurality of preset threat paths of each initial threat element are divided into front preset threat paths and rear preset threat paths;
[0043] Compare each front undetermined threat path with each front preset threat path to obtain front path node coefficients and front node element coefficients, and generate front path coefficients according to the front path node coefficients and the front node element coefficients;
[0044] If the front path coefficients of the front undetermined threat path and each front preset threat path are all less than a preset front path coefficient threshold, the current front undetermined threat path and the corresponding rear undetermined threat path are eliminated;
[0045] If there is a front path coefficient greater than the preset front path coefficient threshold, the rear undetermined threat path corresponding to the front path coefficient and the rear preset threat path corresponding to the front preset threat path are selected and compared to obtain rear path node coefficients and rear node element coefficients;
[0046] According to the rear path node coefficients and the rear node element coefficients, rear path coefficients are generated;
[0047] If the post-path coefficient is greater than the preset post-path coefficient threshold, the corresponding pending threat path is set as a trusted threat path.
[0048] According to the number of trusted threat paths and the corresponding preset attack probability, the credibility of the corresponding initial threat element is generated.
[0049] In some embodiments of the present application, the calculation formula of the credibility of the initial threat element is:
[0050]
[0051] wherein K is the credibility, m1 is the number of trusted threat paths, m0 is the preset threat path number, gs is the preset attack probability of the s-th trusted threat path, k1s is the pre-path coefficient of the s-th trusted threat path, is a preset pre-path coefficient threshold, q1 is a weight coefficient of the pre-path coefficient, k2s is the post-path coefficient of the s-th trusted threat path, q2 is a weight coefficient of the post-path coefficient, is a preset post-path coefficient threshold.
[0052] In some embodiments of the present application, the trusted threat elements are screened out, including:
[0053] A credibility threshold is preset;
[0054] If the credibility is greater than the credibility threshold, the initial threat element is set as a trusted threat element;
[0055] If the credibility is less than the credibility threshold, the initial threat element is set as an untrusted threat element.
[0056] In some embodiments of the present application, according to the influence evaluation value and the change characteristics of the corresponding trusted threat element, a comprehensive ranking value is generated, including:
[0057] According to the number of trusted threat paths of each trusted threat element and the corresponding preset attack type, the attack impact parameter of each trusted threat path is predicted;
[0058] A plurality of attack evaluation indexes are preset;
[0059] According to the attack impact parameter of each trusted threat path, a sub-attack evaluation value of the plurality of attack evaluation indexes is generated, and combined with the weight coefficient of the corresponding attack evaluation index, an attack evaluation value of the corresponding trusted threat path is generated;
[0060] According to the attack evaluation values of the plurality of trusted threat paths of the same trusted threat element and the preset attack probability of the corresponding trusted threat path, an influence evaluation value of the corresponding trusted threat element is generated.
[0061] generate a compensation coefficient according to the change characteristics of the credible threat elements;
[0062] generate a comprehensive ranking value according to the compensation coefficient and the influence evaluation value.
[0063] In some embodiments of the present application, an update instruction of the threat modeling element is generated based on the updated threat element sequence, including:
[0064] sort the plurality of credible threat elements according to the comprehensive ranking value of each credible threat element in the current monitoring period to obtain the updated threat element sequence;
[0065] perform correlation analysis on each credible threat element in the updated threat element sequence and the threat element to be updated in the threat model to obtain a set of associated threat elements of each credible threat element;
[0066] perform conflict analysis on each credible threat element and the threat element to be updated in the corresponding set of associated threat elements, and if there is a conflict, determine the conflict characteristics;
[0067] analyze the conflict characteristics based on the conflict evaluation index, generate a comprehensive conflict evaluation value according to the analysis result, select the corresponding conflict decision according to the comprehensive conflict evaluation value, and perform conflict management until there is no conflict;
[0068] If there is no conflict, generate an update instruction according to the arrangement order of the credible threat elements in the updated threat element sequence and the update period of the threat model.
[0069] In some embodiments of the present application, a real-time updating method of a threat modeling element is also included:
[0070] set a plurality of monitoring points, real-time acquire monitoring parameters of each monitoring point and perform clustering analysis to obtain a plurality of same-dimension monitoring parameter sequences in a current monitoring period, and calculate a change coefficient of each same-dimension monitoring parameter sequence;
[0071] extract the same-dimension monitoring parameter sequence with a change coefficient greater than a preset change coefficient, generate a plurality of initial threat elements, and calculate the credibility of each initial threat element;
[0072] screen out credible threat elements, evaluate the influence evaluation value of each credible threat element, and generate a comprehensive ranking value according to the influence evaluation value and the change characteristics of the corresponding credible threat element;
[0073] sort the plurality of credible threat elements according to the comprehensive ranking value to obtain the updated threat element sequence, and generate an update instruction based on the updated threat element sequence.
[0074] Compared with the prior art, the real-time updating system and method of the threat modeling element according to the embodiments of the present application have the beneficial effects that:
[0075] By constructing several same-dimension monitoring parameter sequences and calculating the change coefficient, generating several initial threat elements according to the change coefficient, calculating the credibility of each initial threat element, determining the credible threat element according to the credibility and constructing an updated threat element sequence, generating an update instruction according to the updated threat element sequence, improving the accuracy of the updated threat element and the identification accuracy of the threat model, and ensuring that the threat model is synchronized with the current threat attack situation. BRIEF DESCRIPTION OF DRAWINGS
[0076] Figure 1 is a schematic diagram of a threat modeling element real-time updating system in an embodiment of the present application;
[0077] Figure 2 is a flowchart of a threat modeling element real-time updating method in an embodiment of the present application. DETAILED DESCRIPTION
[0078] The specific embodiments of the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. The following embodiments are used to illustrate the present application, but not to limit the scope of the present application.
[0079] In the description of the present application, it should be understood that the terms "center", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and therefore cannot be understood as indicating or implying that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.
[0080] The terms "first", "second" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0081] In the description of the present application, it should be noted that, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connection" should be understood in a broad sense, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be direct connection, or indirect connection through an intermediate medium, or internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0082] As Figure 1As shown, the real-time updating system of a threat modeling element in the embodiment of the present application comprises:
[0083] A monitoring module is configured to set a plurality of monitoring points, acquire monitoring parameters of each monitoring point in real time, and perform clustering analysis to obtain a plurality of same-dimension monitoring parameter sequences in a current monitoring period, and calculate a variation coefficient of each same-dimension monitoring parameter sequence.
[0084] An extraction module is configured to extract a same-dimension monitoring parameter sequence with a variation coefficient greater than a preset variation coefficient, generate a plurality of initial threat elements, and calculate a credibility of each initial threat element.
[0085] A screening module is configured to screen credible threat elements, evaluate an influence evaluation value of each credible threat element, and generate a comprehensive ranking value according to the influence evaluation value and a variation characteristic of the corresponding credible threat element.
[0086] An updating module is configured to sort the plurality of credible threat elements according to the comprehensive ranking value to obtain an updated threat element sequence, and generate an updating instruction based on the updated threat element sequence.
[0087] In the embodiment, the monitoring points are set according to the key nodes of the overlay network, the real-time acquisition of the monitoring parameters of each monitoring point refers to the detection and identification of the network space infrastructure such as the host operating system, the business application, the database system, the security device, the audit device, the terminal and the routing device, and the extraction of the monitoring parameters such as the connected coverage, the performance capacity and the terminal characteristics.
[0088] In the embodiment, the same-dimension monitoring parameter sequence refers to the same type of monitoring parameter at the same monitoring point, which is constructed in the time sequence in the monitoring period.
[0089] In some embodiments of the present application, the variation coefficient of each same-dimension monitoring parameter sequence is calculated, comprising:
[0090] determining a first monitoring parameter in each same-dimension monitoring parameter sequence, and calculating a first monitoring parameter difference between the remaining monitoring parameters in the same same-dimension monitoring parameter sequence and the first monitoring parameter;
[0091] generating a first parameter difference sequence of the corresponding same-dimension monitoring parameter sequence according to a plurality of first monitoring parameter differences;
[0092] generating a plurality of parameter difference sequences of each same-dimension monitoring parameter sequence in turn;
[0093] traversing and preprocessing a plurality of parameter difference sequences of the same same-dimension monitoring parameter sequence, wherein the preprocessing includes deleting duplicate data and deleting error data;
[0094] determining a mutation time node in each parameter difference sequence, a mutation feature at the corresponding mutation time node, and performing a first marking, and a continuous change time interval, a continuous change feature in the corresponding continuous change time interval, and performing a second marking according to the pre-processed parameter difference sequence;
[0095] comparing the first markings of the parameter difference sequences of the same same-dimension monitoring parameter sequence to obtain a first marking probability;
[0096] setting the mutation time node and the corresponding mutation feature of the first marking with the first marking probability greater than a preset first marking probability as a mutation factor;
[0097] comparing the second markings of the parameter difference sequences of the same same-dimension monitoring parameter sequence to obtain a second marking probability;
[0098] performing time comparison analysis on the continuous change time interval corresponding to the second marking with the second marking probability greater than a preset second marking probability, and determining a final continuous change time interval according to the analysis result;
[0099] setting the final continuous change time interval and the corresponding continuous change feature as a continuous change factor;
[0100] determining a plurality of mutation factors and a plurality of continuous change factors in the same-dimension monitoring parameter sequence, and generating a change coefficient corresponding to the same-dimension monitoring parameter sequence.
[0101] In this embodiment, the first marking probability refers to the frequency of the same first marking in the plurality of parameter difference sequences of the same same-dimension monitoring parameter sequence. The greater the frequency, the greater the first marking probability, that is, the higher the monitoring accuracy of the corresponding mutation time node and the corresponding mutation parameter value, which lays a foundation for subsequent calculation of the change coefficient.
[0102] In this embodiment, the second marking probability refers to the time interval overlap degree of the same second marking in the plurality of parameter difference sequences of the same same-dimension monitoring parameter sequence. The greater the time interval overlap degree, the greater the second marking probability. The time interval overlap part is taken as the subsequent continuous change time interval, and the subsequent continuous change time interval is analyzed by time comparison. If there is the same time node, the corresponding continuous change time interval is merged to obtain the final continuous change time interval.
[0103] In this embodiment, the mutation feature includes the mutation parameter value and the mutation rate, and the continuous change feature includes the continuous change parameter value, the continuous change rate and the continuous change trend in the continuous change time interval.
[0104] In the embodiment, the mutation factors and the continuous change factors of each same-dimension monitoring parameter sequence are screened out, and the corresponding mutation parameter values and the continuous change parameter values are combined to calculate the change coefficient of the corresponding same-dimension monitoring parameter sequence. According to the change coefficient, whether the corresponding monitoring parameter has a large change and whether there is a threat element are accurately evaluated, which lays a foundation for subsequent updating of threat modeling elements and guarantees updating efficiency and updating accuracy.
[0105] In some embodiments of the present application, the change coefficient of each same-dimension monitoring parameter sequence is calculated, and further includes:
[0106] According to the mutation characteristics in each mutation factor in the same-dimension monitoring parameter sequence, a corresponding mutation factor coefficient is generated;
[0107] According to the continuous change time interval length of each continuous change factor in the same-dimension monitoring parameter sequence and the corresponding continuous change characteristics, a corresponding continuous change factor coefficient is generated;
[0108] According to the plurality of mutation factor coefficients and the plurality of continuous change factor coefficients, a change coefficient of the corresponding same-dimension monitoring parameter sequence is generated;
[0109] The calculation formula of the change coefficient is:
[0110] ;
[0111] Wherein, B is the change coefficient, is the ith mutation factor coefficient, is a preset mutation factor coefficient, n1 is the number of mutation factors of the same-dimension monitoring parameter sequence, n2 is the number of continuous change factors of the same-dimension monitoring parameter sequence, is the ith continuous change factor coefficient, a1 is a first weight coefficient, and a2 is a second weight coefficient.
[0112] In the embodiment, the mutation parameter value, the mutation rate and the mutation trend in the mutation characteristics are converted into values of the same dimension as the mutation factor coefficient. When the mutation parameter value is larger and the mutation rate is faster, the corresponding mutation factor coefficient is larger, and vice versa.
[0113] In the embodiment, the continuous change parameter value, the continuous change rate and the continuous change trend in the continuous change time interval are converted into values of the same dimension as the continuous change factor coefficient. When the continuous change time interval length is longer, the continuous change parameter value is larger, the continuous change rate is faster, and the continuous change trend is continuously rising or falling, the corresponding continuous change factor coefficient is larger, and vice versa.
[0114] In the embodiment, by calculating the plurality of mutation factor coefficients and the plurality of continuous change factor coefficients of the same dimension monitoring parameter sequence, the overall change of the corresponding monitoring parameter in the current monitoring period is accurately evaluated, the corresponding change coefficient is obtained, a foundation is laid for subsequent generation of the initial threat element, and the accuracy of updating the threat element is ensured.
[0115] In some embodiments of the present application, a plurality of initial threat elements are generated, and the credibility of each initial threat element is calculated, including:
[0116] The same dimension monitoring parameter sequence with a change coefficient greater than a preset change coefficient is extracted, and a plurality of mutation factors and a plurality of continuous change factors of the corresponding same dimension monitoring parameter sequence in the current monitoring period are extracted;
[0117] Each mutation factor and each continuous change factor of the corresponding monitoring parameter of the extracted same dimension monitoring parameter sequence is regarded as an initial threat element;
[0118] A plurality of initial threat elements in the current monitoring period are generated in turn;
[0119] A monitoring point position topology graph is constructed, the plurality of initial threat elements are marked on the corresponding monitoring point positions, and based on the attack association information of the monitoring point positions and the time association information between the initial threat elements, a plurality of pending threat paths of each initial threat element are generated;
[0120] Similarity analysis is performed on the initial threat element of each monitoring point position and the preset threat element in the threat element reference library corresponding to the monitoring point position, and a similarity degree is obtained;
[0121] If the maximum similarity degree is less than a preset similarity threshold, the corresponding initial threat element is directly eliminated;
[0122] If there is a similarity degree greater than the preset similarity threshold, a preset threat feature corresponding to the preset threat element is extracted, the preset threat feature includes a plurality of preset attack types, and each preset attack type maps a corresponding attack probability;
[0123] Each preset attack type includes a plurality of preset attack paths, each preset attack path includes a plurality of preset attack point positions, and each preset attack point position maps a corresponding preset attack behavior.
[0124] A plurality of preset threat paths of the corresponding initial threat element are generated according to the extracted preset threat feature;
[0125] The plurality of pending threat paths of each initial threat element are compared with the corresponding plurality of preset threat paths, and the credibility of the corresponding initial threat element is calculated according to the comparison result.
[0126] In the embodiment, the pending threat path is obtained by correlating the seemingly irrelevant monitoring points and the corresponding initial threat elements according to the multi-dimensional correlation analysis and network analysis method, and the possible threat attack path of each initial threat element is obtained. Specifically, the attack correlation information between the monitoring points and the change time nodes of the initial threat elements between different monitoring points are set.
[0127] In the embodiment, the preset threat path is set according to the corresponding preset attack path in the preset threat feature with a similarity greater than a preset similarity threshold. The preset attack path refers to the historical threat attack path generated when the corresponding initial threat element appears.
[0128] In the embodiment, the preset threat path and the pending threat path are compared to obtain the comparison results of the path nodes and the node behaviors of the pending threat path and the preset threat path, so as to determine whether the pending threat path is feasible, and to generate the credibility of the corresponding initial threat element in combination with the corresponding preset attack probability, thereby laying a foundation for subsequent construction and updating of the threat element, ensuring the accuracy of the threat element, and improving the updating accuracy and efficiency.
[0129] In some embodiments of the present application, a plurality of initial threat elements are generated, and the credibility of each initial threat element is calculated. The method further includes:
[0130] Each initial threat element is taken as a division node, and each initial threat element is divided into a front pending threat path and a rear pending threat path.
[0131] Each initial threat element is taken as a division node, and each initial threat element is divided into a front preset threat path and a rear preset threat path.
[0132] Each front pending threat path and each front preset threat path are compared to obtain a front path node coefficient and a front node element coefficient, and a front path coefficient is generated according to the front path node coefficient and the front node element coefficient.
[0133] If the front path coefficients of the front pending threat path and each front preset threat path are all less than a preset front path coefficient threshold, the current front pending threat path and the corresponding rear pending threat path are removed.
[0134] If there is a front path coefficient greater than the preset front path coefficient threshold, the rear pending threat path corresponding to the front path coefficient and the rear preset threat path corresponding to the front preset threat path are selected and compared to obtain a rear path node coefficient and a rear node element coefficient.
[0135] A rear path coefficient is generated according to the rear path node coefficient and the rear node element coefficient.
[0136] If the posterior path coefficient is greater than the preset posterior path coefficient threshold value, the corresponding pending threat path is set as a credible threat path.
[0137] The credibility of the corresponding initial threat element is generated according to the number of credible threat paths and the corresponding preset attack probability.
[0138] In the embodiment, the front path node coefficient refers to the consistency degree of the number and order of the monitoring points involved in the front pending threat path and the front preset threat path. The greater the consistency degree, the greater the corresponding front path node coefficient, and vice versa. The front node element coefficient refers to the consistency degree of the monitoring parameters and change characteristics of the initial threat element at the monitoring point involved in the front pending threat path and the preset attack behavior at the corresponding preset attack point. The greater the consistency degree, the greater the corresponding front node element coefficient, and vice versa. The posterior path node coefficient and the posterior node element coefficient are the same, and will not be described here.
[0139] In the embodiment, the pending threat path and the preset threat path are divided into front pending threat paths, front preset threat paths, rear pending threat paths and rear preset threat paths, and the front path coefficient and the posterior path coefficient are calculated to obtain the credible threat path. The credibility of the corresponding initial threat element is calculated according to the credible threat path, which lays a foundation for subsequent construction and updating of threat elements and improves the updating accuracy.
[0140] In some embodiments of the present application, the calculation formula of the credibility of the initial threat element is:
[0141] ;
[0142] Wherein, K is the credibility, m1 is the number of credible threat paths, m0 is the number of preset threat paths, gs is the preset attack probability of the s-th credible threat path, k1s is the front path coefficient of the s-th credible threat path, is a preset front path coefficient threshold value, q1 is a weight coefficient of the front path coefficient, k2s is the posterior path coefficient of the s-th credible threat path, q2 is a weight coefficient of the posterior path coefficient, is a preset posterior path coefficient threshold value.
[0143] In the embodiment, q1=0.7, q2=0.3.
[0144] In the embodiment, the credibility of the corresponding initial threat element is calculated by calculating the front path coefficient and the posterior path coefficient of each credible threat path. The front path coefficient is the main factor for evaluating the initial threat element, and the posterior path coefficient is the secondary factor for evaluating the initial threat element.
[0145] In the embodiment, the trusted threat path is determined by the front path coefficient and the rear path information, the credibility of the corresponding initial threat element is evaluated according to the number of trusted threat paths of each initial threat element and the preset attack probability, the accuracy of the updated threat element is improved, the error rate of the threat element updating is reduced, and the threat model is synchronized with the current threat attack situation.
[0146] In some embodiments of the present application, the trusted threat element is screened, including:
[0147] The credibility threshold is preset;
[0148] If the credibility is greater than the credibility threshold, the initial threat element is set as a trusted threat element;
[0149] If the credibility is less than the credibility threshold, the initial threat element is set as an untrusted threat element.
[0150] In some embodiments of the present application, the comprehensive ranking value is generated according to the influence evaluation value and the change characteristics of the corresponding trusted threat element, including:
[0151] According to the several trusted threat paths of each trusted threat element and the corresponding preset attack type, the attack influence parameter of each trusted threat path is predicted;
[0152] The several attack evaluation indexes are preset;
[0153] The sub-attack evaluation value of the several attack evaluation indexes is generated according to the attack influence parameter of each trusted threat path, and the attack evaluation value of the corresponding trusted threat path is generated in combination with the weight coefficient of the corresponding attack evaluation index;
[0154] The influence evaluation value of the corresponding trusted threat element is generated according to the attack evaluation values of the several trusted threat paths of the same trusted threat element and the preset attack probability of the corresponding trusted threat path;
[0155] The compensation coefficient is generated according to the change characteristics of the trusted threat element;
[0156] The comprehensive ranking value is generated according to the compensation coefficient and the influence evaluation value.
[0157] In the embodiment, the attack evaluation indexes include but are not limited to the influence degree after the attack success, the importance degree of the attack point, the attack type, the attack range, etc. When the influence degree is greater, the importance degree is greater, and the attack range is greater, the corresponding sub-attack evaluation value is greater, that is, the attack evaluation value is greater, and vice versa. When the attack evaluation value is greater and the preset attack probability is greater, the corresponding influence evaluation value is greater, and vice versa.
[0158] In the embodiment, when the trusted threat element is a mutation factor, the change characteristic is a mutation rate and a mutation value, the change characteristic of the mutation factor is analyzed similarly with the change characteristic of other mutation factors of the same monitoring parameter at the same monitoring point, the mutation time interval of the current trusted threat element is determined according to the similar analysis result, and the compensation coefficient is set according to the mutation time interval. The smaller the mutation time interval is, the greater the compensation coefficient is, and vice versa.
[0159] In the embodiment, when the trusted threat element is a continuous change factor, the change characteristic is a continuous change parameter value, a continuous change rate and a continuous change trend, the change characteristic of the continuous change factor is analyzed similarly with the change characteristic of other continuous change factors of the same monitoring parameter at the same monitoring point, and the continuous change time interval of the current trusted threat element is determined.
[0160] In the embodiment, the comprehensive ranking value is generated by the influence evaluation value and the compensation coefficient. The greater the influence evaluation value and the compensation coefficient are, the greater the corresponding comprehensive ranking value is. The trusted threat elements are ranked according to the size of the comprehensive ranking value, so that the trusted threat elements with large influence evaluation values and fast update are updated first, and the threat model is synchronized with the current threat attack situation.
[0161] In some embodiments of the present application, the update instruction of the threat modeling element is generated based on the update threat element sequence, comprising:
[0162] The several trusted threat elements are ranked according to the comprehensive ranking value of each trusted threat element in the current monitoring period, and the update threat element sequence is obtained;
[0163] Each trusted threat element in the update threat element sequence is analyzed in association with the threat element to be updated in the threat model, and the associated threat element set of each trusted threat element is obtained;
[0164] Each trusted threat element and the threat element to be updated in the corresponding associated threat element set are analyzed for conflict, and if there is a conflict, the conflict characteristic is determined.
[0165] The conflict characteristic is analyzed based on the conflict evaluation index, the comprehensive conflict evaluation value is generated according to the analysis result, the corresponding conflict decision is selected according to the comprehensive conflict evaluation value, and the conflict management is performed until there is no conflict.
[0166] If there is no conflict, the update instruction is generated according to the arrangement order of the trusted threat elements in the update threat element sequence and the update period of the threat model.
[0167] In the embodiment, the conflict feature includes a conflict type and a conflict cause, and the conflict evaluation index includes, but is not limited to, an influence range on a threat model, a change degree on an existing risk, an influence degree on an implemented security control strategy, an influence degree on a business process and a key asset, a potential compliance influence, an implementation cost, a maintenance complexity, etc. When the influence range is smaller, the change degree is smaller, the implementation cost is lower, and the maintenance complexity is lower, the comprehensive conflict evaluation value is smaller, and vice versa.
[0168] In the embodiment, when the comprehensive conflict evaluation value is in a first preset conflict evaluation value interval, the conflict decision is a minimum management decision, including, but not limited to, supplementing a security control of a current trusted threat element, updating a risk acceptance standard, adjusting an effectiveness score of an existing control strategy, etc. When the comprehensive conflict evaluation value is in a second preset conflict evaluation value interval, the conflict decision is a medium management decision, including, but not limited to, locally remodeling an affected component, converting different versions of a trusted threat element, etc. When the comprehensive conflict evaluation value is in a third preset conflict evaluation value interval, the conflict decision is a maximum management decision, including, but not limited to, rebuilding a data flow graph based on a new threat element, establishing a transition mapping table of new and old models, etc.
[0169] In the embodiment, by performing conflict analysis and management on the updated threat element sequence, real-time updating is performed according to the ordering and updating period of the managed updated threat element sequence, the threat element updating accuracy and updating efficiency are improved, and the threat model is ensured to be synchronized with a current threat attack situation.
[0170] In some embodiments of the present application, as shown in Figure 2 the threat modeling element real-time updating method further includes the following steps:
[0171] Step S201: A plurality of monitoring points are set, monitoring parameters of each monitoring point are acquired in real time and are subjected to cluster analysis, a plurality of same-dimension monitoring parameter sequences of a current monitoring period are obtained, and a variation coefficient of each same-dimension monitoring parameter sequence is calculated.
[0172] Step S202: A same-dimension monitoring parameter sequence with a variation coefficient greater than a preset variation coefficient is extracted, a plurality of initial threat elements are generated, and a trustworthiness of each initial threat element is calculated.
[0173] Step S203: A trusted threat element is screened out, an influence evaluation value of each trusted threat element is evaluated, a comprehensive ordering value is generated according to the influence evaluation value and a variation characteristic of the corresponding trusted threat element.
[0174] Step S204: The plurality of trusted threat elements are ordered according to the comprehensive ordering value, an updated threat element sequence is obtained, and an updating instruction is generated based on the updated threat element sequence.
[0175] The above merely describes the preferred embodiments of the present application, and it should be pointed out that, for those skilled in the art, some improvements and replacements can be made without departing from the technical principles of the present application, and these improvements and replacements should also be considered as the protection scope of the present application.
Claims
1. A real-time update system for threat modeling elements, characterized in that, include: The monitoring module is used to set up several monitoring points, acquire the monitoring parameters of each monitoring point in real time, perform cluster analysis, obtain several monitoring parameter sequences of the same dimension for the current monitoring period, and calculate the change coefficient of each monitoring parameter sequence of the same dimension. The extraction module is used to extract the same-dimensional monitoring parameter sequence with a change coefficient greater than the preset change coefficient, generate several initial threat elements, and calculate the credibility of each initial threat element. The filtering module is used to filter out credible threat elements, evaluate the impact assessment value of each credible threat element, and generate a comprehensive ranking value based on the impact assessment value and the change characteristics of the corresponding credible threat element. The update module is used to sort several trusted threat elements according to the comprehensive ranking value, obtain an updated threat element sequence, and generate update instructions based on the updated threat element sequence; Calculate the coefficient of change for each monitoring parameter sequence in the same dimension, including: Determine the first monitoring parameter in each monitoring parameter sequence of the same dimension, and calculate the difference between the remaining monitoring parameters in the same monitoring parameter sequence and the first monitoring parameter of the first monitoring parameter; Generate the first parameter difference sequence corresponding to the same dimension monitoring parameter sequence based on several first monitoring parameter differences; Generate several parameter difference sequences for each monitoring parameter sequence in the same dimension in sequence; The method involves traversing and preprocessing several parameter difference sequences of the same dimension monitoring parameter sequence, wherein the preprocessing includes deleting duplicate data and deleting erroneous data. Based on the preprocessed parameter difference sequences, determine the mutation time nodes and corresponding mutation features in each parameter difference sequence and mark them as first, as well as the continuous change time intervals and corresponding continuous change features in the continuous change time intervals and mark them as second. The first label is compared among several parameter difference sequences of the same dimension monitoring parameter sequence to obtain the first label probability. The mutation time node and the corresponding mutation feature corresponding to the first label whose first label probability is greater than the preset first label probability are set as a mutation factor; The second label is compared among several parameter difference sequences of the same dimension monitoring parameter sequence to obtain the second label probability; A time comparison analysis is performed on the continuous change time interval corresponding to the second label whose second label probability is greater than the preset second label probability, and the final continuous change time interval is determined based on the analysis results. The final continuous change time interval and the corresponding continuous change characteristics are set as a continuous change factor; Identify several mutation factors and several continuous change factors in the same-dimensional monitoring parameter sequence, and generate the change coefficients of the corresponding same-dimensional monitoring parameter sequence; Generate several initial threat elements and calculate the credibility of each initial threat element, including: Extract the same-dimensional monitoring parameter sequence with a change coefficient greater than the preset change coefficient, and extract several mutation factors and several continuous change factors of the corresponding same-dimensional monitoring parameter sequence in the current monitoring period. Each mutation factor and each continuously changing factor of the monitoring parameter corresponding to the extracted same-dimensional monitoring parameter sequence is regarded as an initial threat element. Generate several initial threat elements for the current monitoring period in sequence; Construct a monitoring point topology map, mark several initial threat elements to the corresponding monitoring points, and generate several undetermined threat paths for each initial threat element based on the attack association information of the monitoring points and the time association information between the initial threat elements. The initial threat elements of each monitoring point are compared with the preset threat elements in the threat element reference library of the corresponding monitoring point to obtain the similarity score. If the maximum similarity is less than the preset similarity threshold, the corresponding initial threat element will be directly removed. If there is a similarity greater than a preset similarity threshold, then the preset threat features mapped to the corresponding preset threat elements are extracted. The preset threat features include several preset attack types, and each preset attack type is mapped to a corresponding attack probability. Each preset attack type includes several preset attack paths, each preset attack path includes several preset attack points, and each preset attack point is mapped to a corresponding preset attack behavior. Based on the extracted preset threat features, several preset threat paths corresponding to the initial threat elements are generated; The confidence level of each initial threat element is calculated by comparing several undetermined threat paths with several corresponding preset threat paths and comparing the results. A comprehensive ranking value is generated based on the impact assessment value and the changing characteristics of the corresponding credible threat elements, including: Based on several trusted threat paths for each trusted threat element and the corresponding preset attack types, predict the attack impact parameters for each trusted threat path; Several attack evaluation indicators are pre-defined; Based on the attack impact parameters of each trusted threat path, sub-attack evaluation values of several attack evaluation indicators are generated, and combined with the weight coefficients of the corresponding attack evaluation indicators, the attack evaluation value of the corresponding trusted threat path is generated. The impact evaluation value of the corresponding trusted threat element is generated based on the attack evaluation values of several trusted threat paths of the same trusted threat element and the preset attack probability of the corresponding trusted threat path. Compensation coefficients are generated based on the changing characteristics of credible threat elements; A comprehensive ranking value is generated based on the compensation coefficient and the impact evaluation value.
2. The real-time update system for threat modeling elements as described in claim 1, characterized in that, Calculating the coefficient of change for each monitoring parameter sequence in the same dimension also includes: Generate the corresponding mutation factor coefficient based on the mutation characteristics of each mutation factor in the same dimension monitoring parameter sequence; The corresponding continuous change factor coefficient is generated based on the length of the continuous change time interval and the corresponding continuous change characteristics of each continuously changing factor in the same dimension monitoring parameter sequence. Generate the change coefficients of the corresponding monitoring parameter sequence in the same dimension based on multiple mutation factor coefficients and multiple continuous change factor coefficients; The formula for calculating the coefficient of variation is: ; Where B is the coefficient of variation. The coefficient of the i1th mutation factor. Here, n1 represents the number of mutation factors in the same-dimensional monitoring parameter sequence, and n2 represents the number of continuously changing factors in the same-dimensional monitoring parameter sequence. Let a1 be the coefficient of the i2th continuously changing factor, and a2 be the first weighting coefficient and the second weighting coefficient.
3. The real-time update system for threat modeling elements as described in claim 2, characterized in that, The process includes generating several initial threat elements, calculating the credibility of each initial threat element, and also: Using each initial threat element as a dividing node, the several pending threat paths of each initial threat element are divided into pre-pending threat paths and post-pending threat paths; Using each initial threat element as a dividing node, the several preset threat paths of each initial threat element are divided into a pre-preset threat path and a post-preset threat path; Each pending threat path is compared with each preset threat path to obtain the previous path node coefficient and the previous node element coefficient. The previous path coefficient is generated based on the previous path node coefficient and the previous node element coefficient. If the path coefficients of both the current pending threat path and each of the previous preset threat paths are less than the preset path coefficient threshold, then the current pending threat path and its corresponding subsequent pending threat path will be removed. If a preceding path coefficient is greater than a preset preceding path coefficient threshold, then the subsequent undetermined threat path corresponding to the preceding path coefficient and the subsequent preset threat path corresponding to the preceding preset threat path are selected and compared to obtain the subsequent path node coefficient and the subsequent node element coefficient. Generate the post-path coefficients based on the post-path node coefficients and the post-path element coefficients; If the subsequent path coefficient is greater than the preset subsequent path coefficient threshold, the corresponding pending threat path will be set as a trusted threat path. The credibility of the initial threat element is generated based on the number of trusted threat paths and the corresponding preset attack probabilities.
4. The real-time update system for threat modeling elements as described in claim 3, characterized in that, The formula for calculating the credibility of the initial threat element is as follows: ; Where K is the trust level, m1 is the number of trusted threat paths, m0 is the preset number of threat paths, gs is the preset attack probability of the s-th trusted threat path, and k1s is the previous path coefficient of the s-th trusted threat path. Let q1 be the weighting coefficient of the preceding path coefficient, k2s be the weighting coefficient of the following path coefficient of the s-th trusted threat path, and q2 be the weighting coefficient of the following path coefficient. This is the preset threshold for the post-path coefficient.
5. The real-time update system for threat modeling elements as described in claim 4, characterized in that, Trusted threat elements were identified, including: Pre-set a credibility threshold; If the credibility is greater than the credibility threshold, the initial threat element will be set as a trusted threat element; If the credibility is less than the credibility threshold, the initial threat element will be set as an untrusted threat element.
6. The real-time update system for threat modeling elements as described in claim 5, characterized in that, Update instructions for generating threat modeling elements based on updated threat element sequences include: Based on the comprehensive ranking value of each trusted threat element in the current monitoring period, several trusted threat elements are sorted to obtain an updated threat element sequence; Each trusted threat element in the updated threat element sequence is correlated with the threat element to be updated in the threat model to obtain the set of associated threat elements for each trusted threat element; Perform conflict analysis between each trusted threat element and the threat elements to be updated in the corresponding set of associated threat elements. If a conflict exists, determine the conflict characteristics. The conflict characteristics are analyzed based on the conflict evaluation indicators. A comprehensive conflict evaluation value is generated based on the analysis results. The corresponding conflict decision is selected based on the comprehensive conflict evaluation value, and conflict management is carried out until there is no conflict. If there is no conflict, an update instruction is generated according to the order of trusted threat elements in the updated threat element sequence and the update cycle of the threat model.
7. A method for real-time updating of threat modeling elements, characterized in that, include: Set up several monitoring points, acquire the monitoring parameters of each monitoring point in real time and perform cluster analysis to obtain several monitoring parameter sequences of the same dimension for the current monitoring period, and calculate the change coefficient of each monitoring parameter sequence of the same dimension. Extract the same-dimensional monitoring parameter sequence with a change coefficient greater than the preset change coefficient, generate several initial threat elements, and calculate the credibility of each initial threat element; Trusted threat elements are selected, and the impact assessment value of each trusted threat element is evaluated. A comprehensive ranking value is generated based on the impact assessment value and the change characteristics of the corresponding trusted threat elements. Several trusted threat elements are sorted according to the comprehensive ranking value to obtain an updated threat element sequence, and an update instruction is generated based on the updated threat element sequence; Calculate the coefficient of change for each monitoring parameter sequence in the same dimension, including: Determine the first monitoring parameter in each monitoring parameter sequence of the same dimension, and calculate the difference between the remaining monitoring parameters in the same monitoring parameter sequence and the first monitoring parameter of the first monitoring parameter; Generate the first parameter difference sequence corresponding to the same dimension monitoring parameter sequence based on several first monitoring parameter differences; Generate several parameter difference sequences for each monitoring parameter sequence in the same dimension in sequence; The method involves traversing and preprocessing several parameter difference sequences of the same dimension monitoring parameter sequence, wherein the preprocessing includes deleting duplicate data and deleting erroneous data. Based on the preprocessed parameter difference sequences, determine the mutation time nodes and corresponding mutation features in each parameter difference sequence and mark them as first, as well as the continuous change time intervals and corresponding continuous change features in the continuous change time intervals and mark them as second. The first label is compared among several parameter difference sequences of the same dimension monitoring parameter sequence to obtain the first label probability. The mutation time node and the corresponding mutation feature corresponding to the first label whose first label probability is greater than the preset first label probability are set as a mutation factor; The second label is compared among several parameter difference sequences of the same dimension monitoring parameter sequence to obtain the second label probability; A time comparison analysis is performed on the continuous change time interval corresponding to the second label whose second label probability is greater than the preset second label probability, and the final continuous change time interval is determined based on the analysis results. The final continuous change time interval and the corresponding continuous change characteristics are set as a continuous change factor; Identify several mutation factors and several continuous change factors in the same-dimensional monitoring parameter sequence, and generate the change coefficients of the corresponding same-dimensional monitoring parameter sequence; Generate several initial threat elements and calculate the credibility of each initial threat element, including: Extract the same-dimensional monitoring parameter sequence with a change coefficient greater than the preset change coefficient, and extract several mutation factors and several continuous change factors of the corresponding same-dimensional monitoring parameter sequence in the current monitoring period. Each mutation factor and each continuously changing factor of the monitoring parameter corresponding to the extracted same-dimensional monitoring parameter sequence is regarded as an initial threat element. Generate several initial threat elements for the current monitoring period in sequence; Construct a monitoring point topology map, mark several initial threat elements to the corresponding monitoring points, and generate several undetermined threat paths for each initial threat element based on the attack association information of the monitoring points and the time association information between the initial threat elements. The initial threat elements of each monitoring point are compared with the preset threat elements in the threat element reference library of the corresponding monitoring point to obtain the similarity score. If the maximum similarity is less than the preset similarity threshold, the corresponding initial threat element will be directly removed. If there is a similarity greater than a preset similarity threshold, then the preset threat features mapped to the corresponding preset threat elements are extracted. The preset threat features include several preset attack types, and each preset attack type is mapped to a corresponding attack probability. Each preset attack type includes several preset attack paths, each preset attack path includes several preset attack points, and each preset attack point is mapped to a corresponding preset attack behavior. Based on the extracted preset threat features, several preset threat paths corresponding to the initial threat elements are generated; The confidence level of each initial threat element is calculated based on the comparison results by comparing several potential threat paths with several corresponding preset threat paths. A comprehensive ranking value is generated based on the impact assessment value and the changing characteristics of the corresponding credible threat elements, including: Based on several trusted threat paths for each trusted threat element and the corresponding preset attack types, predict the attack impact parameters for each trusted threat path. Several attack evaluation indicators are pre-defined; Based on the attack impact parameters of each trusted threat path, sub-attack evaluation values of several attack evaluation indicators are generated, and combined with the weight coefficients of the corresponding attack evaluation indicators, the attack evaluation value of the corresponding trusted threat path is generated. The impact evaluation value of the corresponding trusted threat element is generated based on the attack evaluation values of several trusted threat paths of the same trusted threat element and the preset attack probability of the corresponding trusted threat path. Compensation coefficients are generated based on the changing characteristics of credible threat elements; A comprehensive ranking value is generated based on the compensation coefficient and the impact evaluation value.
Citation Information
Patent Citations
Threat scoring method and device and electronic equipment
CN116015899A
Financial risk data management method based on machine learning
CN117726439A