Method for mining APT attack high-order decision rule based on Semiorder relationship

By constructing high-order decision rules through Semiorder relationships, the problem of difficulty in capturing correlation in APT detection is solved, and efficient and accurate identification and real-time defense against APT attacks are achieved.

CN120602114APending Publication Date: 2025-09-05XIAN THERMAL POWER RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510530477.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing APT detection methods are based on the behavior of a single event and have difficulty capturing the deep correlations between the various stages of APT, leading to problems such as delayed detection and high false alarm rates.

Method used

The semiorder relationship is used to construct high-order decision rules. By prioritizing and comparing event attribute values, association rules between multiple events are generated. Accuracy and coverage are used to screen high-quality decision rules, and a rule base is built for real-time detection.

Benefits of technology

It significantly improves the accuracy and real-time detection of APT attacks, reduces the false alarm rate and missed alarm rate, and enhances the real-time and accuracy of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602114A_ABST
    Figure CN120602114A_ABST
Patent Text Reader

Abstract

The invention provides a mining method of an APT attack high-order decision rule based on a Semiorder relationship, which comprises the following steps: collecting multi-attribute network behavior data from a target network, including a timestamp, a port number, a protocol type, a connection state, session duration, a connection frequency, a geographic position and an APT attack identifier, and preprocessing the data to obtain an APT attack high-order decision rule; removing redundancy and abnormities, filling missing values and performing standardization processing to generate a cleaning data set; constructing an order information table based on the cleaning data set; according to the sequence information table, applying a Semiorder relationship, and defining a high-order decision rule of the APT attack; performing screening according to the accuracy rate and the coverage rate of the high-order decision rule to obtain a target decision rule; and storing the target decision rule in a rule base, detecting real-time network behavior data based on the rule base, and judging whether an event conforming to APT attack characteristics exists in a target network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security and data mining technology, and in particular to a method for mining high-order decision rules of APT attacks based on Semiorder relations. Background Art

[0002] Advanced persistent threats (APTs) are planned, organized attacks characterized by the attacker's ability to remain lurking within target networks for extended periods, conducting multi-stage, covert attacks. APT attacks involve complex attack chains and multi-stage behaviors, where the correlations between these stages are difficult to capture using traditional single-event attribute mining methods. Existing APT detection methods are typically based on single-event behaviors, such as traffic analysis or anomaly detection. However, these methods are limited in their ability to capture the deep correlations between APT stages, leading to problems such as delayed detection and high false positive rates.

[0003] High-order decision rules are a method for mining complex associations between pairs of events. By analyzing the relationships between different event attribute values, association rules between multiple events can be generated. In this invention, Semiorder is a special binary relationship used to prioritize and compare the specific attribute values ​​of these events, more accurately identifying APT attacks. The priority relationship provided by Semiorder makes the learning and application of high-order decision rules more targeted and reliable. Summary of the Invention

[0004] A first aspect of the present disclosure provides a method for mining high-order decision rules of APT attacks based on a semi-order relationship, comprising:

[0005] Collect multi-attribute network behavior data from the target network, including timestamps, port numbers, protocol types, connection status, session duration, connection frequency, geographic location, and APT attack identifiers. Preprocess the data to remove redundancy, eliminate anomalies, fill in missing values, and standardize to generate a cleansed dataset.

[0006] Constructing a sequence information table based on the cleaned data set;

[0007] Applying the Semiorder relation according to the sequence information table to define a high-order decision rule for the APT attack;

[0008] Screening is performed according to the accuracy and coverage of the high-order decision rules to obtain a target decision rule;

[0009] The target decision rule is stored in a rule base, and real-time network behavior data is detected based on the rule base to determine whether there are events in the target network that meet the characteristics of APT attacks.

[0010] In combination with the first aspect, the sequence information table is constructed based on the cleaned data set according to the following formula:

[0011] S=(U,A t =C∪D,{V a |a∈A t},{I a |a∈A t},{R a |a∈AT})),

[0012] Among them, U is a finite non-empty set of events, A t is an attribute set, including conditional attributes C and decision attributes D, V a is the value range of attribute a, a∈A t , I a is the information function, R a It is V a The binary relationship above.

[0013] In combination with the first aspect, the application of the Semiorder relation according to the sequence information table to define the high-order decision rule of the APT attack includes using the Semiorder relation as R a In V a A binary relation on , where the Semiorder relation satisfies asymmetry, Ferrers condition, and semitransitivity.

[0014] In combination with the first aspect, the high-order decision rule is formalized as the following formula:

[0015]

[0016] Among them, φ and is a semiorder relation on the set U.

[0017] In combination with the first aspect, the target decision rule is obtained by screening according to the accuracy and coverage of the high-level decision rule, and the rule having a greater than preset accuracy and a greater than preset coverage is screened by the following formula:

[0018]

[0019] in, is the accuracy of the high-order decision rule,

[0020] is the coverage of the high-order decision rule,

[0021]

[0022] Among them, x and y are network behaviors.

[0023] According to a second aspect of the present disclosure, an electronic device is provided, comprising:

[0024] one or more processors;

[0025] A storage unit is used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors can implement the method for mining high-order decision rules of APT attacks based on Semiorder relationships.

[0026] According to a third aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the method for mining high-order decision rules of APT attacks based on Semiorder relationships can be implemented.

[0027] The method for mining high-level decision rules for APT attacks based on semiorder relationships, provided by this paper, gradually mines high-level decision rules that demonstrate APT attack characteristics by constructing an event attribute priority model based on semiorder relationships. This method enables in-depth correlation analysis of multi-stage APT attack behaviors. This method can more accurately capture the hidden relationships between events at each stage in the APT attack chain, effectively reducing false positive and false negative rates, improving the accuracy and real-time performance of APT attack detection, and meeting the requirements for identifying complex APT attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 Schematic diagram of the process of mining high-order decision rules of APT attacks based on Semiorder relationships according to an embodiment of the present disclosure;

[0029] Figure 2 Schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0030] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different drawings represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present disclosure.

[0031] The terms used in the embodiments of the present disclosure are for the purpose of describing specific embodiments only and are not intended to limit the embodiments of the present disclosure. The singular forms "a," "the," and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0032] like Figure 1 FIG. 1 is a flow chart of a method for mining high-order decision rules of APT attacks based on Semiorder relationships according to an embodiment of the present disclosure, including:

[0033] S101: Collect multi-attribute network behavior data from the target network, including timestamp, port number, protocol type, connection status, session duration, connection frequency, geographic location, and APT attack identifier, and pre-process the data to remove redundancy, eliminate anomalies, fill in missing values, and standardize the data to generate a cleansed data set;

[0034] S102: Constructing a sequence information table based on the cleaned data set;

[0035] S103: Applying the Semiorder relationship according to the sequence information table to define a high-order decision rule for the APT attack;

[0036] S104: Screening according to the accuracy and coverage of the high-level decision rules to obtain a target decision rule;

[0037] S105: Storing the target decision rule in a rule base, and detecting real-time network behavior data based on the rule base to determine whether there is an event in the target network that meets the characteristics of an APT attack.

[0038] Specifically, S101: Data Collection and Preprocessing. In this preliminary stage, the system collects network behavior data of various attributes from the target network. The data includes:

[0039] Timestamp: records the specific time when an event occurs, providing time series information for subsequent behavior analysis.

[0040] Port number: includes source port number and destination port number, which helps to identify the specific input and output ports of the network connection.

[0041] Protocol type: This field identifies the network protocol used for data packet transmission (e.g., TCP, UDP, etc.), which helps analyze traffic patterns.

[0042] Connection Status: Indicates whether the connection is successful, which helps to screen for possible abnormal behavior.

[0043] Session Duration: reflects the length of the connection and can be used to identify connections that have been inactive for a long time.

[0044] Connection frequency: The number of connections within a certain time range helps identify abnormal connection behavior.

[0045] Geographic Location: Provides geographic information of source and target devices, helping to analyze potential attack sources.

[0046] APT attack identification: Identifies whether it is a known APT attack incident, which helps with subsequent model training and verification.

[0047] During the preprocessing process, the data undergoes redundant data removal, outlier elimination, missing value filling, and standardization to ensure data quality and improve the accuracy and reliability of subsequent analysis.

[0048] S102: Constructing a sequence information table. Building a sequence information table based on the cleaned dataset is a crucial step in this method. The sequence information table records the attributes and value ranges of network events, providing a structured data foundation for subsequent rule definition based on semiorder relationships. This table effectively integrates multidimensional data to form a comprehensive event description.

[0049] S103: Define high-level decision rules. Based on the constructed sequence information table, apply the semiorder relationship to define high-level decision rules for APT attacks. The introduction of the semiorder relationship further refines the relationships between attribute values. By prioritizing them, the complex correlations between different attribute values ​​can be effectively captured. This step is the core of implementing high-level decision rules, allowing the system to deeply analyze the potential relationships between different events.

[0050] S104: Filter target decision rules. After obtaining high-level decision rules, the system screens the rules based on accuracy and coverage. Accuracy measures the proportion of correctly identified events to all predicted events, while coverage refers to the proportion of correctly identified events to all actual events. These two metrics can effectively identify high-quality decision rules, thereby improving detection reliability.

[0051] S105: Storing and Applying the Rule Base. Finally, the filtered target decision rules are stored in the rule base. This rule base is used to detect real-time network behavior data. By applying these decision rules, the system can promptly determine whether there are events in the target network that match APT attack characteristics. This step ensures the system's real-time and high efficiency in practical applications, thereby enhancing its defense capabilities against APT attacks.

[0052] Beneficial Effects: Through the above steps, this method achieves efficient detection and accurate identification of APT attacks. Compared with traditional methods, this method utilizes a priority model based on semiorder relationships to capture the correlation between events at a deeper level, significantly improving the detection capability of complex attack behaviors, thereby effectively reducing the false positive rate and missed negative rate, and enhancing the real-time and accuracy of network security protection.

[0053] Furthermore, the sequence information table is constructed based on the cleaned data set according to the following formula:

[0054] S=(U,A t =C∪D,{V a |a∈A t},{I a |a∈A t},{R a |a∈AT})),

[0055] Among them, U is a finite non-empty set of events, A t is an attribute set, including conditional attributes C and decision attributes D, V a is the value range of attribute a, a∈A t , I a is the information function, R a It is V a The binary relationship above.

[0056] Specifically, the event set is a finite, non-empty set of events encompassing all network behavior events collected from the target network. Each event reflects a specific behavior occurring within the network, such as logins and data transmissions. The completeness of this set is fundamental to analysis, ensuring that all potential attack behaviors within the network are covered.

[0057] The attribute set consists of two parts: conditional attributes and decision attributes. Conditional attributes are usually used to describe the characteristics of an event, while decision attributes are the result of classifying or judging network behavior.

[0058] Example: Conditional attributes: such as timestamp, port number, protocol type, etc. These attributes help analyze the context and environment of the event.

[0059] Decision attribute: For example, APT attack identification, this attribute is used to indicate whether the event is judged to be the result of an APT attack.

[0060] Attribute range: The attribute range represents all possible values ​​for the attribute. It provides a complete description of the attribute, ensuring comprehensive analysis. For example, the port number range can be 0-65535, and the protocol type can be TCP, UDP, etc.

[0061] The information function characterizes each attribute and maps attribute values ​​to corresponding amounts of information. It provides a quantitative assessment of attribute importance. Information functions can help better understand the role of each attribute in event analysis and support decision-making.

[0062] Binary relations represent relationships across attribute value domains, defining the connections between attribute values. This relationship provides the foundation for the subsequent application of semiorder relations. For example, there may be a fixed relationship between port numbers and protocol types, such as certain protocols typically using specific ports.

[0063] By constructing and analyzing the sequence information table in detail, we can provide strong support for the detection and defense of APT attacks, making the network security protection system more complete and efficient. This method not only improves the ability to process complex network behavior data, but also provides a scientific basis for decision-making.

[0064] Furthermore, the application of the Semiorder relation according to the sequence information table to define the high-order decision rule of the APT attack includes using the Semiorder relation as R a In V a A binary relation on , where the Semiorder relation satisfies asymmetry, Ferrers condition, and semitransitivity.

[0065] Specifically, asymmetry: for any two events x and y,

[0066] If xφy holds, then yφx does not. Ensure that relationships between events are explicit, avoiding circular relationships so that priorities can be clearly established during decision-making. For example, in the context of APT attacks, the presence of certain features will take precedence over others, which facilitates effective classification and discrimination.

[0067] Fe rr ers: This condition ensures the consistency of decision rules, that is, it can maintain consistency and predictability when processing similar events. This is particularly important for analyzing complex attack patterns, because the lack of certain features may lead to the misidentification of APT attacks.

[0068] Half-pass: Semi-transitivity allows rules to preserve complex relational networks to a certain extent, allowing for analysis of indirect relationships between events. This provides flexibility for the construction of high-order decision rules, enabling them to better adapt to changes in dynamic network environments.

[0069] The semiorder relationship is used as the domain of event attribute values. This means that for each attribute value, there is a semiorder relationship between its possible values. This relationship allows for more in-depth comparison and analysis between different attribute values.

[0070] For example, in network behavior, the access frequency of a specific port (such as port 80 and port 443) can be considered as two attribute values. Using the Semiorder relationship, we can establish the priority of different port access behaviors and identify which behaviors are more likely to be related to APT attacks.

[0071] By using the constructed Semiorder relation, we can define the high-order decision rule for APT attacks, which can be formalized as the following relation: This rule indicates that when the conditions are met, the event will be judged as an APT attack.

[0072] Furthermore, the high-order decision rule is formalized as the following formula:

[0073]

[0074] Among them, φ and is a semiorder relation on the set U.

[0075] Furthermore, the target decision rule is obtained by screening according to the accuracy and coverage of the high-level decision rules, and the rules with greater than a preset accuracy and greater than a preset coverage are screened by the following formula:

[0076]

[0077] in, is the accuracy of the high-order decision rule,

[0078] is the coverage of the high-order decision rule,

[0079]

[0080] Among them, x and y are network behaviors.

[0081] Specifically, the high-order decision rule is formalized using the following formula:

[0082]

[0083] Among them, φ and They represent conditions and conclusions, or can be understood as the relationship between "triggering events" and "resulting events". For example, a specific network behavior sequence φ may trigger or imply another specific network behavior This forms a correlation judgment of the APT attack pattern.

[0084] This formulaic rule definition can analyze the sequence of network events and reveal the hidden patterns of APT attack behavior through the logical connection between conditions and conclusions.

[0085] In order to evaluate the effectiveness of high-order decision rules, their accuracy and coverage are quantitatively assessed to screen out rules that meet the preset standards.

[0086] Accuracy It is defined that among all event pairs that satisfy the condition φ, the conclusion can be satisfied at the same time. The ratio is calculated as follows:

[0087]

[0088] m(φ) is the set of all event pairs that satisfy the condition φ, that is, the instance of the φ relation on the event set U×U.

[0089] Satisfies both φ and The set of all event pairs is the intersection instance of two relations. The accuracy reflects the precision of the rules and ensures the accuracy of the mined rules in APT attack identification.

[0090] Coverage Define that among all pairs of events that satisfy the conclusion φ, the condition The ratio is:

[0091]

[0092] To meet the conclusion The set of all event pairs. is to satisfy φ and A collection of event pairs.

[0093] Coverage reflects the scope of a rule, meaning the applicability or universality of the rule in APT attack behaviors.

[0094] By calculating the accuracy and coverage of each rule, you can filter out rules that meet the preset thresholds to ensure the effectiveness of the rules in the application:

[0095] Preset accuracy threshold: Only rules with an accuracy greater than the preset threshold are considered high-confidence rules and thus used for APT detection.

[0096] Preset coverage threshold: Only rules with coverage greater than the preset threshold are considered sufficiently general to ensure their applicability in multiple scenarios.

[0097] Optional, rule-based filtering mechanism based on preset thresholds allows for real-time updating of the rule base. As new APT attack patterns are discovered, the accuracy and coverage thresholds of the rules can be dynamically adjusted, allowing the rule base to adapt to the ever-changing network security landscape.

[0098] By defining different φ and Combining these conditions can form a multi-level APT attack detection logic. For example, by combining different conditions to form a multi-level, progressive decision tree, the coverage and detection accuracy of APT attack identification can be further improved.

[0099] The electronic device 200 may be a desktop computer, a notebook, a PDA, a cloud server, or other electronic device. The electronic device 200 may include but is not limited to a processor 201 and a memory 202. Those skilled in the art will appreciate that Figure 2 This is merely an example of the electronic device 200 and does not constitute a limitation of the electronic device 200. The electronic device 200 may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.

[0100] The processor 201 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0101] The memory 202 can be an internal storage unit of the electronic device 200, such as a hard disk or memory of the electronic device 200. The memory 202 can also be an external storage device of the electronic device 200, such as a plug-in hard disk equipped on the electronic device 200, a smart memory card (SMC), a secure digital (SD) card, a flash card, etc. Furthermore, the memory 202 can also include both an internal storage unit of the electronic device 200 and an external storage device. The memory 202 is used to store the computer program 203 and other programs and data required by the electronic device. The memory 202 can also be used to temporarily store data that has been output or is about to be output.

[0102] In the embodiments provided in the present disclosure, it should be understood that the disclosed devices / electronic devices and methods can be implemented in other ways. For example, the device / electronic device embodiments described above are merely schematic. For example, the division of modules or units is merely a logical function division. In actual implementation, there may be other division methods. Multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection of devices or units, which may be electrical, mechanical or other forms.

[0103] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0104] In addition, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0105] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present disclosure implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by the processor, it can implement the steps of the above-mentioned various method embodiments. The computer program may include computer program code, which may be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0106] The above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than to limit them. Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present disclosure, and should all be included in the scope of protection of the present disclosure.

Claims

1. A method for mining high-order decision rules of APT attacks based on Semiorder relations, characterized by: include: Collect multi-attribute network behavior data from the target network, including timestamps, port numbers, protocol types, connection status, session duration, connection frequency, geographic location, and APT attack identifiers. Preprocess the data to remove redundancy, eliminate anomalies, fill in missing values, and standardize to generate a cleansed dataset. Constructing a sequence information table based on the cleaned data set; Applying the Semiorder relation according to the sequence information table to define a high-order decision rule for the APT attack; Screening is performed according to the accuracy and coverage of the high-order decision rules to obtain a target decision rule; The target decision rule is stored in a rule base, and real-time network behavior data is detected based on the rule base to determine whether there are events in the target network that meet the characteristics of APT attacks.

2. The method according to claim 1, characterized in that The sequence information table is constructed based on the cleaned data set according to the following formula: S=(U,A t =C∪D,{V a |a∈A t },{I a |a∈A t },{R a |a∈AT})), Among them, U is a finite non-empty set of events, A t is an attribute set, including conditional attributes C and decision attributes D, V a is the value range of attribute a, a∈A t , I a is the information function, R a It is V a The binary relationship above.

3. The method according to claim 2, characterized in that The application of the Semiorder relation according to the sequence information table to define the high-order decision rule of the APT attack includes using the Semiorder relation as R a In V a A binary relation on , where the Semiorder relation satisfies asymmetry, Ferrers condition, and semitransitivity.

4. The method according to claim 1, wherein The high-order decision rule is formalized as the following formula: Among them, φ and is a semiorder relation on the set U.

5. The method according to claim 1, wherein The target decision rule is obtained by screening based on the accuracy and coverage of the high-level decision rules, and the rules with greater than the preset accuracy and greater than the preset coverage are screened by the following formula: in, is the accuracy of the high-order decision rule, is the coverage of the high-order decision rule, m(φ)={(x,y)∈U×U|(x,y)|=φ}, Among them, x and y are network behaviors.

6. An electronic device, characterized in that: include: one or more processors; A storage unit for storing one or more programs, which, when executed by the one or more processors, enables the one or more processors to implement the method for mining high-order decision rules for APT attacks based on Semiorder relationships according to any one of claims 1 to 5.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it can implement the method for mining APT attack high-order decision rules based on Semiorder relations according to any one of claims 1 to 5.