A network attack intent prediction method and related equipment based on ATT&CK

By constructing and completing the attack chain using the ATT&CK-based network attack intent prediction method, and using a large model and knowledge base to determine attack tactics and intent, the problem of low accuracy in network attack intent prediction in existing technologies is solved, and more efficient network security protection is achieved.

CN120658431BActive Publication Date: 2026-02-03PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510708352.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2026-02-03
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively counter complex or covert cyberattacks, resulting in low accuracy in predicting cyberattack intent.

Method used

By using the ATT&CK-based network attack intent prediction method, the initial attack event is captured, an incomplete attack technique chain is constructed, and the chain is completed using a pre-set knowledge base and a large model to determine the attack tactics and intent. The prompt information is dynamically updated to improve the prediction accuracy.

Benefits of technology

It improves the accuracy of predicting network attack intentions, enhances the understanding and identification of attack chains, and improves the level of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658431B_ABST
    Figure CN120658431B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a network attack intention prediction method based on ATT&CK and related equipment, and belongs to the technical field of network security. The method comprises the following steps: determining initial skill and tactics information and initial context information corresponding to each attack technology based on an incomplete initial attack technology link composed of attack technologies adopted by an extracted attack event; obtaining initial prompt information based on the initial attack technology link, the initial skill and tactics information and the initial context information; inputting the initial attack technology link and the initial prompt information into a target large model to obtain at least one target attack tactic link after the initial attack technology link is completed and determine a corresponding attack sub-intention set, updating the initial prompt information according to the attack sub-intention set to obtain updated prompt information, inputting the target attack technology link and the updated prompt information into the target large model and outputting a target attack intention. The application can improve the accuracy of the predicted network attack intention.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method and related equipment for predicting network attack intent based on ATT&CK. Background Technology

[0002] ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is an open-source framework for adversarial tactics and techniques. It constructs a systematic classification system of tactics and techniques by extracting and summarizing real-world cyber threat events.

[0003] In order to predict the attacker's ultimate intention (such as data theft, system damage, etc.) from various attack operations and respond quickly to defense, related technologies often predict the attacker's next possible action based on the attack operations that occur at the current point in time. Since such prediction methods cannot fully capture the long-term strategic changes of attackers, they are difficult to effectively deal with complex or covert attacks, resulting in low accuracy of the network attack intent predicted in the end. Summary of the Invention

[0004] The main objective of this application is to propose a network attack intent prediction method and related equipment based on ATT&CK, aiming to improve the accuracy of the predicted network attack intent.

[0005] To achieve the above objectives, a first aspect of this application proposes a method for predicting network attack intent based on ATT&CK, the method comprising:

[0006] Capture multiple initial attack events from the target system, extract at least two attack events from the multiple initial attack events, and form an incomplete initial attack technique chain based on the attack techniques adopted by the extracted attack events.

[0007] Based on the pre-set ATT&CK knowledge base, the initial technical and tactical information corresponding to each attack technique is determined, the initial context information corresponding to each attack event is determined by parsing each attack event, and the initial prompt information under multi-dimensional semantics is obtained based on the initial attack technique link, the initial technical and tactical information and the initial context information.

[0008] The initial attack technology link and initial prompt information are input into the preset target large model to obtain at least one target attack technology link corresponding to the initial attack technology link after it is completed. The target attack tactical link to which the target attack technology link belongs is determined based on the ATT&CK knowledge base.

[0009] The attack sub-intent set of the target attack tactical link is determined. The initial prompt information is updated based on the attack sub-intent set to obtain the updated prompt information. The target attack tactical link and the updated prompt information are input into the target large model to predict the target attack intent corresponding to the initial attack tactical link.

[0010] In some embodiments, multiple initial attack events are captured from the target system, including:

[0011] Capture basic attribute information and related attribute information belonging to the same attack identifier from the target system. The basic attribute information includes at least descriptive information and attack occurrence time information, and the related attribute information includes at least attack technique information, affected asset information and attack status information.

[0012] Based on basic attribute information and related attribute information, the initial attack event under the hierarchical data structure is captured.

[0013] In some embodiments, at least two attack events are extracted from multiple initial attack events, and an incomplete initial attack technique chain is formed based on the attack techniques employed by the extracted attack events, including:

[0014] Different first weights are assigned to the basic attribute information and the associated attribute information, and the defense coverage of each initial attack event is evaluated based on the first weights to obtain the corresponding confidence value;

[0015] Based on the ATT&CK knowledge base, multiple initial attack events are classified into different tactical phases, and at least two attack events are extracted from at least two tactical phases based on confidence values.

[0016] By connecting the corresponding attack techniques according to the attack time sequence of the attack events, an incomplete initial attack technique chain is obtained.

[0017] In some embodiments, the initial attack technique chain and initial prompt information are input into a preset target large model to obtain at least one target attack technique chain corresponding to the completed initial attack technique chain, including:

[0018] The initial attack technique chain and initial prompt information are input into the preset target large model, and predefined attack logic constraint rules are obtained;

[0019] Based on attack logic constraint rules, identify at least one technical break in the initial attack technique chain;

[0020] Based on the initial prompt information, the speculative attack technique associated with the technical gap is determined, and the speculative attack technique is inserted into the technical gap to obtain the target attack technique link corresponding to the completed initial attack technique link.

[0021] In some embodiments, the target attack tactical chain includes multiple attack tactics;

[0022] Determine the set of attack sub-intents in the target attack tactical chain, including:

[0023] Identify the speculative attack events corresponding to speculative attack techniques, and analyze the speculative attack events to determine the corresponding speculative context information;

[0024] Extract the first key field corresponding to the current attack tactic from the initial context information or inferred context information corresponding to any attack tactic, and determine at least one adjacent attack tactic corresponding to the current attack tactic.

[0025] The second key field corresponding to the adjacent attack tactics is extracted from the initial context information or inferred context information corresponding to the adjacent attack tactics;

[0026] Based on the first and second key fields, determine the context association fields corresponding to the current attack tactic;

[0027] Based on adjacent attack tactics and context association fields, the attack sub-intent corresponding to the current attack technique is determined, and the attack sub-intents of all attack techniques are integrated to obtain a set of attack sub-intents.

[0028] In some embodiments, updated prompt information is obtained by updating the initial prompt information based on the attack sub-intent set, including:

[0029] Based on the ATT&CK knowledge base, we determine the updated tactics and techniques corresponding to the speculative attack techniques.

[0030] The initial prompt information is updated based on the target attack tactical link, inferred context information, updated tactical information and attack sub-intent set to obtain updated prompt information under multi-dimensional semantics.

[0031] In some embodiments, the target attack intent corresponding to the initial attack technique chain is predicted, including:

[0032] When there are multiple attack tactical links for the target system, obtain the scenario information corresponding to the target system.

[0033] Based on scenario information, a corresponding second weight is set for each preset weight factor. The weight factors include at least historical attack frequency information, attack complexity value, asset sensitivity value, vulnerability exposure face value, and consequence severity value.

[0034] Based on each weighting factor and its corresponding second weight, the threat score corresponding to each target attack tactical link is evaluated; based on the threat score, each target attack tactical link is sorted, and the target attack intent corresponding to a preset number of target attack tactical links is predicted and output.

[0035] In some embodiments, after predicting the target attack intent corresponding to the initial attack technique chain, the method further includes:

[0036] Obtain information about the current attack phase of the target system;

[0037] The attack phase information, target attack tactical links, and corresponding target attack intentions are input into the target big model, and the target system's defense strategy information is output.

[0038] To achieve the above objectives, a second aspect of this application provides a network attack intent prediction device based on ATT&CK, the device comprising:

[0039] The acquisition module is used to capture multiple initial attack events from the target system, extract at least two attack events from the multiple initial attack events, and form an incomplete initial attack technique chain based on the attack techniques adopted by the extracted attack events.

[0040] The initial prompt information module is used to determine the initial technical and tactical information corresponding to each attack technique based on the preset ATT&CK knowledge base, parse each attack event to determine the corresponding initial context information, and obtain the initial prompt information under multi-dimensional semantics based on the initial attack technique link, initial technical and tactical information and initial context information.

[0041] The completion module is used to input the initial attack technology link and initial prompt information into the preset target large model to obtain at least one target attack technology link corresponding to the initial attack technology link after completion, and to determine the target attack tactical link to which the target attack technology link belongs based on the ATT&CK knowledge base. The target attack tactical link includes multiple attack tactics.

[0042] The target prediction module is used to determine the set of attack sub-intents of the target attack tactical link, update the initial prompt information based on the set of attack sub-intents to obtain updated prompt information, input the target attack tactical link and the updated prompt information into the target large model, and predict the target attack intent corresponding to the initial attack tactical link.

[0043] To achieve the above objectives, a third aspect of the present application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the network attack intent prediction method based on ATT&CK described in the first aspect.

[0044] To achieve the above objectives, a fourth aspect of the present application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the network attack intent prediction method based on ATT&CK of the first aspect described above.

[0045] This application proposes a network attack intent prediction method and related equipment based on ATT&CK. It captures multiple initial attack events from the target system, extracts at least two attack events from these initial events, and constructs an incomplete initial attack technique chain based on the attack techniques employed by the extracted attack events. Next, it determines the initial tactical information corresponding to each attack technique based on a pre-set ATT&CK knowledge base, parses each attack event to determine the corresponding initial context information, and obtains multi-dimensional semantic initial prompt information based on the initial attack technique chain, initial tactical information, and initial context information. This initial prompt information provides multi-faceted threat risk understanding and response suggestions, enabling the subsequent target large-scale model to complete the initial attack chain based on the initial prompt information. The initial attack technique chain and initial warning information are input into a preset target model to obtain at least one target attack technique chain corresponding to the completed initial attack technique chain. Based on the ATT&CK knowledge base, the target attack tactical chain to which the target attack technique chain belongs is determined. The attack sub-intent set of the target attack tactical chain is determined, and the initial warning information is updated according to the attack sub-intent set to obtain updated warning information. The target attack technique chain and updated warning information are input into the target model to predict the target attack intent corresponding to the initial attack technique chain. In this way, the initial warning information is dynamically updated to obtain updated warning information, which helps to identify the attacker's potential strategies and next actions in a timely manner and improves the accuracy of the final predicted target attack intent. Attached Figure Description

[0046] Figure 1 This is a schematic diagram of an optional implementation environment for the network attack intent prediction device based on ATT&CK provided in this application embodiment;

[0047] Figure 2 This is an optional flowchart of the network attack intent prediction method based on ATT&CK provided in the embodiments of this application;

[0048] Figure 3 yes Figure 2 Step 101 in the flowchart is an optional implementation.

[0049] Figure 4 yes Figure 2 Another optional implementation flowchart for step 101;

[0050] Figure 5 yes Figure 2 Step 103 is an optional implementation flowchart;

[0051] Figure 6 yes Figure 2 Step 104 in the flowchart is an optional implementation.

[0052] Figure 7 yes Figure 2 Another optional implementation flowchart for step 104 in the diagram;

[0053] Figure 8 yes Figure 2 Step 104 in the flowchart is another optional implementation.

[0054] Figure 9 yes Figure 2 Step 104 in the flowchart is another optional implementation.

[0055] Figure 10 This is another optional flowchart of the network attack intent prediction method based on ATT&CK provided in the embodiments of this application;

[0056] Figure 11 This is a schematic diagram of an optional device module of the network attack intent prediction device based on ATT&CK provided in the embodiments of this application;

[0057] Figure 12 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0059] It should be noted that although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0060] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0061] First, let's analyze the terms used in this application:

[0062] Natural Language Processing (NLP): NLP uses computers to process, understand, and utilize human language (such as Chinese and English). NLP is a branch of artificial intelligence and an interdisciplinary field of computer science and linguistics, often referred to as computational linguistics. NLP includes syntactic analysis, semantic analysis, and discourse understanding. It is commonly used in machine translation, handwritten and printed character recognition, speech recognition and text-to-speech conversion, intent recognition, information extraction and filtering, text classification and clustering, sentiment analysis, and opinion mining. It involves data mining, machine learning, knowledge acquisition, knowledge engineering, artificial intelligence research, and linguistic research related to language computation.

[0063] Next, the technical background related to the embodiments of this application will be introduced:

[0064] In recent years, zero-day exploits, ransomware as a service, and advanced persistent threats (APTs) have exhibited multi-stage and highly covert characteristics, posing increasingly severe challenges to current cybersecurity defense systems. In real-world network environments, attackers conduct phased attacks using discrete combinations of attack techniques or tactics (such as initial access and lateral movement). Traditional defense technologies are often limited to analyzing single steps or individual events, making it difficult to correlate local behaviors and infer the final attack intent in the early stages of an attack, resulting in a defense response lagging behind the attack process.

[0065] Based on this, in order to predict the attacker's ultimate intention (such as data theft, system damage, etc.) from various attack operations and respond quickly to defense, related technologies often predict the attacker's next possible operation based on the attack operations that occur at the current point in time. Since such prediction methods cannot fully capture the long-term strategic changes of attackers, they are difficult to effectively deal with complex or covert attacks, resulting in low accuracy of the network attack intent predicted in the end.

[0066] Furthermore, embodiments of this application provide a method and related equipment for predicting network attack intentions based on ATT&CK, aiming to improve the accuracy of the predicted network attack intentions.

[0067] For example, such as Figure 1 As shown, Figure 1This is a schematic diagram of an optional implementation environment for the ATT&CK-based network attack intent prediction device provided in this application embodiment. The implementation environment includes a client 11 and a server 12, wherein the client 11 and the server 12 are connected through a communication network, and the ATT&CK-based network attack intent prediction device (which can also be simply referred to as the "prediction device" for ease of description) can be deployed on the server 12. In practical application, server 12 captures multiple initial attack events from client 11 and extracts at least two attack events from these initial attack events. Based on the attack techniques adopted by the extracted attack events, an incomplete initial attack technique chain is formed. Next, based on a preset ATT&CK knowledge base, the initial tactical information corresponding to each attack technique is determined, and the initial context information corresponding to each attack event is determined by parsing each attack event. Based on the initial attack technique chain, the initial tactical information, and the initial context information, initial prompt information under multi-dimensional semantics is obtained. Then, the initial attack technique chain and the initial prompt information are input into a preset target large model to obtain at least one target attack technique chain corresponding to the completed initial attack technique chain. Based on the ATT&CK knowledge base, the target attack technique chain to which the target attack technique chain belongs is determined, where the target attack tactical chain includes multiple attack tactics. After that, the attack sub-intent set of the target attack tactical chain is determined, and the initial prompt information is updated according to the attack sub-intent set to obtain updated prompt information. The target attack technique chain and the updated prompt information are input into the target large model to predict the target attack intent corresponding to the initial attack technique chain. Thus, the embodiments of this application can improve the understanding and identification of attack chains in practical applications, thereby improving the accuracy of predicted network attack intentions and effectively enhancing the level of network security protection.

[0068] The server 12 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms. Additionally, the server 12 can also be a node server in a blockchain network. The client 11 can be a mobile phone, computer, smart voice interaction device, smart wearable device, smart home appliance, in-vehicle terminal, etc., but is not limited to these. The client 11 and server 12 can be connected directly or indirectly through wired or wireless communication, and this embodiment of the application does not impose any limitations.

[0069] It should be noted that in this application embodiment, when information related to user characteristics, such as basic user information or user identity, is required, the user's permission or consent will be obtained first. Furthermore, the collection, use, and processing of this data will comply with relevant laws, regulations, and standards. In addition, when this application embodiment needs to obtain sensitive personal information of a user, the user's separate permission or consent will be obtained first. Only after obtaining the user's separate permission or consent will the necessary data for the normal operation of this application embodiment be obtained. For example, before obtaining the initial attack event, this application embodiment will obtain the authorization or consent of relevant personnel; otherwise, obtaining the initial attack event cannot be applied to this application embodiment. Furthermore, all other relevant data obtained by the prediction device of this application are authorized data, and will not be elaborated upon here.

[0070] In this application embodiment, the description will focus on the prediction device, which can be integrated into a computer device, such as a server. Figure 2 As shown, Figure 2 This is an optional flowchart of the network attack intent prediction method based on ATT&CK provided in the embodiments of this application. Figure 2 The method may include, but is not limited to, the following steps 101 to 105. When the training device executes the network attack intent prediction method based on ATT&CK, the specific process is as follows. It should be noted first that this embodiment... Figure 2 The order of steps 101 to 105 is not specifically limited. The order of steps can be adjusted or some steps can be reduced or added according to actual needs.

[0071] Step 101: Capture multiple initial attack events from the target system, extract at least two attack events from the multiple initial attack events, and form an incomplete initial attack technique chain based on the attack techniques adopted by the extracted attack events.

[0072] Step 101 will be described in detail below.

[0073] The target system refers to a network system that has been attacked or has the potential to be attacked. The target system can be a computer, server, network device, or a network system composed of these devices. The initial attack event refers to multiple attack events (attack steps) initially detected in the target system that may constitute a network threat. Initial attack events can be various types of security logs, alerts, network traffic data, etc., such as a suspicious login attempt, an unauthorized file access, or the execution of malware. Furthermore, the extracted "initial attack events" are referred to as "attack events."

[0074] Each attack event includes detailed information from multiple aspects, which together constitute a complete description of the attack event. The attack techniques are determined from this detailed information, describing the specific attack methods or means employed by the attacker when executing the corresponding attack event. Furthermore, the attack techniques corresponding to the extracted attack events are sequentially connected to form an initial attack technique chain. This initial attack technique chain reflects the technological evolution process employed by the attacker from the start of the attack to achieving a specific objective. It should be noted that the initial attack technique chain is usually incomplete; the individual attack techniques within the initial attack technique chain cannot constitute a complete attack chain.

[0075] Furthermore, in this embodiment of the application, an incomplete initial attack chain is constructed by selecting key attack events from the target system, so that the initial attack chain can be completed later, and then the attacker's final intention to execute a series of attack events can be predicted based on the completed chain.

[0076] In some embodiments, such as Figure 3 As shown, Figure 3 yes Figure 2 Step 101, an optional implementation flowchart, captures multiple initial attack events from the target system, including the following steps:

[0077] 101.1.1 Capture basic attribute information and associated attribute information belonging to the same attack identifier from the target system. The basic attribute information includes at least descriptive information and attack occurrence time information. The associated attribute information includes at least attack technique information, affected asset information, and attack status information.

[0078] 101.1.2 Based on basic attribute information and related attribute information, the initial attack event under the hierarchical data structure is captured.

[0079] Steps 101.1.1 to 101.1.2 are described in detail below.

[0080] This application redefines the schema of the initial attack event, specifically by hierarchically describing the rich attributes and relationships of the entity type "initial attack event." Unlike traditional static, pre-defined designs, this application, through its hierarchical schema design, can dynamically extract and update relevant knowledge about the initial attack event based on real-time data and contextual information. This design flexibility allows the prediction device to quickly adapt to newly emerging initial attack events, while traditional technologies often rely on static definitions, making it difficult to cope with rapidly changing network security environments.

[0081] Among them, the attack identifier is a label or code used to uniquely identify information related to a specific attack event. It helps the predictive device identify which data belongs to the same attack event from massive amounts of data, and can subsequently manage different attack events in a unified manner based on the attack identifier.

[0082] Furthermore, basic attribute information is fundamental data describing the initial attack event, and it includes at least the following:

[0083] (1) Description information is textual information used to describe the initial attack event, including but not limited to a textual overview of the initial attack event, an overview or technical description of the attack techniques used, and the impact of the current initial attack event. Description information can help the prediction device understand the content and characteristics of the initial attack event.

[0084] (2) Attack occurrence time information, which is used to record the specific time when the initial attack event occurred, which helps to analyze the temporal correlation of the corresponding initial attack event.

[0085] Furthermore, the associated attribute information is additional data related to the initial attack event, and it includes at least the following:

[0086] (1) Attack technique information, which describes the attack techniques used by the attacker. For example, attack technique information may include spear phishing, exploiting public vulnerabilities, etc.

[0087] (2) Impacted asset information, which describes the assets or systems affected by the attack, such as the attacked servers, databases or network devices.

[0088] (3) Attack status information: It is used to describe the current status of the initial attack event, such as whether the attack is still in progress, whether it has been blocked, or whether it has caused damage.

[0089] For example, the initial attack event is defined as follows:

[0090]

[0091]

[0092] Furthermore, this application embodiment also defines the schema of the initial attack chain based on the schema of the initial attack event. Therefore, a stepOrder field can be added to the schema of the initial attack event, which is used to characterize the order of the attack event in the initial attack chain if the current initial attack event is extracted.

[0093] It should be noted that, in addition to the minimum covered content, more fields can be added to the basic attribute information and related attribute information according to the actual situation, so that the initial attack event contains more information available for analysis, thereby helping to infer the final attack intent. In other words, the specific content included in the basic attribute information and related attribute information can be adaptively adjusted according to the actual situation, and the embodiments of this application do not impose any limitations on this.

[0094] In some embodiments, such as Figure 4 As shown, Figure 4 yes Figure 2 Another optional implementation flowchart for step 101 involves extracting at least two attack events from multiple initial attack events, and forming an incomplete initial attack technique chain based on the attack techniques employed by the extracted attack events, including the following steps:

[0095] 101.2.1 Different first weights are assigned to the basic attribute information and the associated attribute information, and the defense coverage of each initial attack event is evaluated based on the first weights to obtain the corresponding confidence values;

[0096] 101.2.2 Based on the ATT&CK knowledge base, multiple initial attack events are classified into different tactical stages, and at least two attack events are extracted from at least two tactical stages based on confidence values;

[0097] 101.2.3 Connect the corresponding attack techniques according to the attack time sequence of the attack events to obtain an incomplete initial attack technique chain.

[0098] Steps 101.2.1 to 101.2.3 are described in detail below.

[0099] In some embodiments, for attack techniques that already have relatively good defense measures or have been patched by current mainstream systems, their defense coverage is usually relatively high. In this case, the probability of an attacker using the attack technique is low, or in other words, its attack threat coefficient to the target system is relatively low. For this purpose, the embodiments of this application will prioritize extracting initial attack events with low defense coverage when constructing the initial attack chain.

[0100] The first weight is used to characterize the importance of different attribute information in assessing the defense coverage of an attack event. For example, a larger first weight is assigned to related attribute information, and a smaller first weight is assigned to basic attribute information. It should be noted that the "first" here is only used to distinguish it from the "second" mentioned later, and does not represent any other special meaning. Furthermore, the first weight can be preset, or it can be intelligently predicted by an intelligent module set in the prediction device. The specific setting can be determined according to the actual situation, and this application embodiment does not impose any restrictions on it.

[0101] The confidence score characterizes the target system's assessment of the true threat posed by an initial attack event; that is, the probability or confidence level that the target system considers the initial attack event to be a real event with a significant potential threat. The confidence score is calculated by assigning different first weights to basic attribute information and related attribute information, and combining this with the actual content of each attribute information. For example, the calculation method could be to pre-define threat-sensitive words, and calculate the confidence score based on the threat-sensitive words appearing in the basic attribute information and their corresponding first weights; or, for instance, to iterate through each word in the description information, increasing the base score if any threat-sensitive word appears, until the total base score for the description information is obtained.

[0102] Furthermore, the confidence score reflects whether the system should pay attention to the initial attack event, the magnitude of its potential harm, and the reliability of its successful detection. A higher confidence score indicates a lower level of defense coverage for the initial attack event and a greater potential attack threat risk; conversely, a lower confidence score indicates that the initial attack event may be a false alarm or have a low risk.

[0103] Furthermore, the first weight can be assigned to the description information and attack occurrence time information belonging to the basic attribute information, as well as the attack technology information, affected asset information, and attack status information belonging to the associated attribute information, in order to refine the importance of various types of information in the defense coverage assessment. Thus, the prediction device can integrate multi-dimensional information to accurately measure the risk level of the corresponding initial attack event, thereby selecting the initial attack event with a low defense coverage as the extracted attack event.

[0104] The ATT&CK knowledge base is an open-source framework for adversarial tactics and techniques. It extracts and summarizes real-world cyber threat events to build a systematic classification system of tactics and techniques, helping technical personnel and organizations better understand and respond to cybersecurity threats. The main components of ATT&CK include:

[0105] (1) Tactics: These refer to the goals or stages an attacker undertakes when carrying out a cyberattack, such as initial access, execution, persistence, privilege escalation, defense bypass, credential access, exploration and discovery, lateral movement, information gathering, command and control, data leakage, and impact. These tactics represent the high-level goals that attackers attempt to achieve; classifying multiple initial attack events into different tactical stages refers to identifying the tactics corresponding to the extracted attack events.

[0106] (2) Techniques: These are the specific methods or means used by attackers to achieve a particular tactic. For example, under the "initial access" tactic, attackers may use techniques including, but not limited to, spear phishing and exploiting public vulnerabilities. Spear phishing refers to sending targeted emails that trick recipients into clicking on malicious links or attachments; exploiting public vulnerabilities refers to using known vulnerabilities in publicly available applications to launch attacks.

[0107] (3) Sub-technique: Sub-technique is a further refinement of the technique. It refers to the specific steps or practices taken in the actual attack process, and describes in detail how to implement a certain technique to achieve the attacker's tactical goal.

[0108] Furthermore, since the ATT&CK knowledge base provides a systematic classification standard and a unified semantic framework, which describes in detail the classification of various attack techniques, tactics and related attack behaviors, the prediction device can classify the initial attack events based on the ATT&CK knowledge base and various information details of the initial attack events to determine the tactics to which each initial attack event belongs.

[0109] Furthermore, in real-world network environments, due to considerations such as efficiency and stealth, it is uncommon to use multiple techniques under the same tactic. Attackers typically employ different attack techniques across multiple tactical phases to achieve their ultimate attack intent. Therefore, to ensure the high credibility of key nodes in the constructed incomplete initial attack chain, thereby improving the accuracy of subsequent determination of the target's attack intent, the prediction device extracts attack events from the initial attack events under at least two tactical phases based on confidence values. In other words, the extracted attack events belong to at least two different tactics.

[0110] Furthermore, after determining the confidence value corresponding to each initial attack event, the initial attack events with high confidence can be extracted as attack events to be analyzed. Then, according to the time sequence of the extracted attack events, each attack event is connected in turn to construct a more complete and reliable attack chain, which helps to further understand the attacker's behavior path and predict the target's attack intent.

[0111] Furthermore, the schema of the initial attack chain is also redefined in this embodiment. For example, the initial attack chain can be defined as follows, where Text represents the specific information carried after each field, and the specific content of Text can be adaptively adjusted according to the actual situation:

[0112]

[0113] Furthermore, the initial attack technology chain is usually incomplete, because the purpose of this application embodiment is to predict the attacker's final attack intent based on the incomplete attack chain, so as to identify the attacker's target attack intent from discrete attack behaviors as soon as possible in the early stage of the attack in practical applications. At the same time, this incompleteness also prompts the prediction device to continuously improve its detection capabilities, thereby improving the accuracy of the target attack intent predicted by the target large model in subsequent continuous supplementation of the prediction.

[0114] Step 102: Based on the preset ATT&CK knowledge base, determine the initial technical and tactical information corresponding to each attack technique, analyze each attack event to determine the corresponding initial context information, and obtain the initial prompt information under multi-dimensional semantics based on the initial attack technique link, initial technical and tactical information and initial context information.

[0115] Step 102 is described in detail below.

[0116] The initial tactical and technical information refers to the tactical and technical information related to a specific attack event. This information can be determined through mapping using the ATT&CK knowledge base. For example, if an attack event employs a "spear phishing attack," it can be mapped to corresponding tactics and techniques based on the ATT&CK knowledge base, thereby obtaining the relevant tactical and technical information. An example of initial tactical and technical information extracted for a possible attack technique is as follows:

[0117]

[0118] It should be noted that the level of detail of the tactical and technical information included in the initial tactical and technical information can be adaptively adjusted according to the actual situation. Furthermore, the representation of the initial tactical and technical information is not limited to the above examples and can also be represented in the form of structured text. This application embodiment does not impose any restrictions on this.

[0119] The initial context information includes various information related to the attack event and system information related to the target system. This initial context information can be determined based on basic and related attribute information, which helps the prediction device understand and analyze the corresponding attack behavior. Furthermore, the prediction device can generate initial prompt information with rich semantic layers through fusion, association, and reasoning in a multi-dimensional semantic space. This initial prompt information can provide multi-faceted understanding of threat risks and response suggestions, so that the target large model can subsequently complete the initial attack chain based on the initial prompt information.

[0120] Step 103: Input the initial attack technology link and initial prompt information into the preset target large model to obtain at least one target attack technology link corresponding to the completed initial attack technology link, and determine the target attack tactical link to which the target attack technology link belongs based on the ATT&CK knowledge base.

[0121] Step 103 will be described in detail below.

[0122] Here, the target big model refers to a pre-trained deep learning model with powerful reasoning and generation capabilities. It can complete the initial attack technique chain based on initial prompts to generate a complete target technique chain and target attack tactic chain, thereby supporting subsequent final intent recognition and prediction. Furthermore, the target big model can be:

[0123] (1) Generative Pre-trained Transformer (GPT): The GPT series models (such as GPT-4) have natural language understanding and generation capabilities. Therefore, in this application embodiment, the GPT series models can be used as the target large model to infer the complete target technology link and the target tactical link corresponding to the target technology link based on the initial input prompt information.

[0124] (2) Graph Neural Networks (GNNs): GNNs are deep learning models specifically designed to process graph structure data. Furthermore, they can store initial attack events, initial technical and tactical information, etc., in the form of graphs, and then use the large target model of graph neural networks to capture the complex dependencies between nodes and complete the initial attack chain.

[0125] (3) Bidirectional Encoder Representations from Transformers (BERT): BERT is a pre-trained language model that understands the contextual relationships in the input data through bidirectional training. BERT can be fine-tuned for various natural language processing (NLP) tasks, including text classification, named entity recognition, and question answering systems. In the field of cybersecurity, BERT can be used to analyze unstructured text data such as threat intelligence reports and security log descriptions.

[0126] It should be noted that the target large model can be specifically selected according to the actual situation. That is, the target large model can also be a recurrent neural network (RNN) model, a convolutional neural network (CNN) model, etc. The embodiments of this application do not limit the specific type of the target large model.

[0127] The target attack technology chain refers to a complete technology path after completion. It includes the attack techniques corresponding to the current attack events, as well as a series of attack techniques that the attacker might employ based on the current attack behavior, as predicted by the target large-scale model. Furthermore, the number of target attack technology chains predicted by the target large-scale model can be one or more. For example, for an initial attack technology chain A→C→D, where A, C, and D are all attack techniques, the completed target attack technology chain may only contain A→B→C→D, or it may include A→B→C→D or A→B→C→D→E. Furthermore, the target attack tactical chain is determined based on the tactics corresponding to each attack technique within the target attack technology chain.

[0128] Furthermore, the target attack technology chain focuses on the specific techniques used by attackers during the attack process, helping the target big model analyze attack behavior from the attack technology level; while the target attack tactics chain focuses on the strategic goals and overall tactical objectives of the attack, helping the target big model analyze attack behavior from the attack tactics level; thus, the target big model can understand a series of attack behaviors from different dimensions at the same time, so as to achieve more accurate prediction of target attack intentions in the future.

[0129] In some embodiments, such as Figure 5 As shown, Figure 5 yes Figure 2 Step 103, an optional implementation flowchart, involves inputting the initial attack technique chain and initial prompt information into a preset target large model to obtain at least one target attack technique chain corresponding to the completed initial attack technique chain, including the following steps:

[0130] 103.1.1 Input the initial attack technique chain and initial prompt information into the preset target large model, and obtain the predefined attack logic constraint rules;

[0131] 103.1.2 Based on attack logic constraint rules, identify at least one technical break in the initial attack technique chain;

[0132] 103.1.3 Based on the initial prompt information, determine the speculative attack technique associated with the technical gap, and insert the speculative attack technique into the technical gap to obtain the target attack technique link corresponding to the completed initial attack technique link.

[0133] Steps 103.1.1 to 103.1.3 are described in detail below.

[0134] Among them, attack logic constraint rules are the logical relationships and restrictions on attack behaviors. They are used to regulate and constrain the rationality of attack paths, ensuring that the attack chain conforms to the actual attack strategy and process. This guides the target large model to analyze the relationships between various attack techniques in the current initial attack technique chain and identify potential gaps or omissions. Furthermore, attack logic constraint rules can be predefined by relevant experts or intelligently generated by another large model. This application embodiment does not limit the specific generation method of attack logic constraint rules, and adjustments can be made according to the actual situation.

[0135] For example, the attack logic constraint rules include, but are not limited to, the following:

[0136] (1) Time sequence rule: The attacker must gain initial access before he can make lateral movement. This means that when analyzing the initial attack chain, any lateral movement technique must occur after the initial access.

[0137] (2) Dependency Rule: Some attack techniques depend on the successful implementation of other techniques. For example, an attacker must first successfully access or escalate privileges before stealing data. Therefore, when analyzing the attack chain, it is essential to ensure that the data theft step follows the data access step.

[0138] (3) Environmental constraints: Some attack techniques may only be effective in specific operating system or application environments. For example, some malware may only target Windows systems. Therefore, when analyzing attack chains, the threat risk of these attack techniques can only be considered when the target system is Windows.

[0139] (4) Attacker target rule: The attacker’s goal may be to obtain sensitive data or to damage the system. When analyzing the initial attack chain, any attack technique should be consistent with the attacker’s ultimate goal. For example, if the attacker’s goal is to steal data, techniques that are not related to system damage should not be considered.

[0140] (5) Success rate rule: Some attack techniques have a low success rate in specific environments, so these techniques can be excluded during analysis. For example, if a certain attack technique is proven unsuccessful in the target system, the unsuccessful attack technique can be ignored when determining the technical gap in the initial attack chain.

[0141] In this context, a "technical gap" refers to a technical void or missing link in the initial attack chain, meaning a point where a certain technical operation is not detected or not clearly connected to subsequent steps. Identifying gaps helps inferring unknown techniques or next actions that the attacker might employ. Furthermore, an initial attack chain must contain at least one technical gap. For example, if an initial attack chain is A→C→D, the target model can determine that there is at least one technical gap in this initial attack chain based on attack logic constraints and initial warning information.

[0142] Specifically, speculative attack techniques are inferred from the target's large-scale model based on the known initial attack chain, technical gaps, and initial warning information. These speculative attack techniques are likely to be employed by the attacker but not directly observed. They are then inserted into the technical gaps to complete the incomplete initial attack chain, resulting in the target attack technique chain. Further, the attack tactics to which each attack technique in the target attack technique chain belongs are determined using the ATT&CK knowledge base, thus obtaining the corresponding target attack tactical chain. The target attack tactical chain includes multiple attack tactics.

[0143] Step 104: Determine the set of attack sub-intents of the target attack tactical link, update the initial prompt information according to the set of attack sub-intents to obtain updated prompt information, input the target attack tactical link and the updated prompt information into the target large model, and predict the target attack intent corresponding to the initial attack tactical link.

[0144] Step 104 is described in detail below.

[0145] The attack sub-intent set is based on the specific sub-goals or tasks pursued by the attacker at different stages, as determined by the target attack tactical chain. Each sub-intent corresponds to a specific attack target or behavior. The updated prompt information is obtained by supplementing or adjusting the initial prompt information based on the attack sub-intent set. The updated prompt information can more accurately reflect the latest state or potential intent of the current attack behavior, thereby improving the accuracy of the target large model prediction.

[0146] In this context, the target attack intent refers to the ultimate goal or core objective pursued by the attacker during the attack process. It reflects the strategic intent behind a series of attack behaviors corresponding to the target attack technology chain, such as stealing sensitive information, disrupting normal system operation, or controlling critical infrastructure. Based on the target attack intent, relevant personnel can better understand the attacker's motives and goals, thereby predicting their possible subsequent actions and helping to develop targeted defense strategies.

[0147] Furthermore, in this embodiment of the application, the attack sub-intent determined from the target attack tactical chain is used to dynamically update the initial prompt information to obtain updated prompt information, thereby helping to identify the attacker's potential strategies and next actions in a timely manner and improving the accuracy of the final determined target attack intent.

[0148] In some embodiments, such as Figure 6 As shown, Figure 6 yes Figure 2 Step 104, an optional implementation flowchart, identifies the set of attack sub-intents in the target attack tactical chain, including the following steps:

[0149] 104.1.1 Identify the speculative attack events corresponding to the speculative attack techniques, and analyze the speculative attack events to determine the corresponding speculative context information;

[0150] 104.1.2 Extract the first key field corresponding to the current attack tactic from the initial context information or inferred context information corresponding to any attack tactic, and determine at least one adjacent attack tactic corresponding to the current attack tactic;

[0151] 104.1.3 Extract the second key field corresponding to the adjacent attack tactics from the initial context information or inferred context information corresponding to the adjacent attack tactics;

[0152] 104.1.4 Based on the first key field and the second key field, determine the context association field corresponding to the current attack tactic;

[0153] 104.1.5 Based on adjacent attack tactics and context association fields, determine the attack sub-intent corresponding to the current attack technique, and integrate the attack sub-intents of all attack techniques to obtain a set of attack sub-intents.

[0154] Steps 104.1.1 to 104.1.5 are described in detail below.

[0155] In this context, speculative attack events refer to unconfirmed potential attack events inferred from speculative attack techniques. This involves analyzing and speculating on possible attack behaviors, which are used to expand the completeness of the attack chain and predict future attack actions. Speculative contextual information refers to background or environmental details related to the attack behavior derived or integrated from the speculative attack event. Like the initial contextual information, it serves to support and enrich the understanding of the speculative attack event.

[0156] Furthermore, since the target attack tactical chain includes multiple attack tactics, the attack technique corresponding to any attack tactic may be pre-extracted or inferred. Therefore, the context information corresponding to the attack technique may be initial context information or inferred context information. When the attack technique corresponding to the attack tactic is an initial attack technique, its corresponding context information is initial context information; when the attack technique corresponding to the attack tactic is an inferred attack technique, its corresponding context information is inferred context information.

[0157] The first key field represents the most important identifying field extracted from the context information corresponding to a specific attack tactic. It represents the core characteristics or main parameters of the current attack tactic and is used to distinguish and locate the specific manifestation of the attack tactic. Adjacent attack tactics refer to the preceding (preceding) or following (subsequent) attack tactic in the attack tactic chain. They represent continuous action links in the attack process and are used to analyze the evolution of the attack path and potential next attack behaviors. The second key field refers to the second key parameter extracted from the context information corresponding to adjacent attack tactics.

[0158] Among them, by analyzing the relationship between the first key field and the second key field, a contextual association field is formed that can describe the relationship between the current attack tactic and adjacent attack tactics. This helps to understand the relationship and impact between the current attack tactic and adjacent attack tactics.

[0159] Here, attack sub-intention refers to the intention between the current attack tactic and adjacent attack tactics. The set of attack sub-intentions is the collection of all attack sub-intentions in the target attack tactic chain. Attack sub-intentions can be determined based on two adjacent attack tactics or based on the attack techniques corresponding to the attack tactics. For example, if the attack sub-intention of a certain attack technique T1204 is determined to be "inducing interaction" at the technical level, the target big model can determine its attack sub-intention at the attack tactic level (such as data theft) based on the ability of the ATT&CK knowledge base to analyze contextual information and pre- and post-causal relationship features.

[0160] Furthermore, in this embodiment of the application, by determining the set of attack sub-intents in the target attack tactical link, the initial prompt information is dynamically updated accordingly, thereby improving the accuracy and targeting of attack intent prediction; then the updated prompt information and the attack technology link are input into the target large model together, thereby more accurately identifying the deep intent behind the attack behavior.

[0161] In some embodiments, such as Figure 7 As shown, Figure 7 yes Figure 2 Another optional implementation flowchart for step 104 involves updating the initial prompt information based on the attack sub-intent set to obtain updated prompt information, including the following steps:

[0162] 104.2.1 Determine the updated tactical and technical information corresponding to speculative attack techniques based on the ATT&CK knowledge base;

[0163] 104.2.2 The initial prompt information is updated based on the target attack tactical link, inferred context information, updated tactical information and attack sub-intent set to obtain updated prompt information under multi-dimensional semantics.

[0164] Steps 104.2.1 to 104.2.2 are described in detail below.

[0165] Updating tactical and technical information refers to the tactical and technical information corresponding to each inferred attack technique, determined based on the ATT&CK knowledge base. Updating alert information refers to a comprehensive update of the initial alert information after considering relevant information from multiple dimensions (target attack tactical chain, inferred context information, updated tactical and technical information, and attack sub-intent set, etc.). This update is not merely a simple correction of information, but rather a richer and more accurate alert information through multi-faceted analysis and integration. In this way, the target big model can better understand the attacker's series of attack behaviors and ultimate attack intent, thereby improving the ability to identify potential threats and the accuracy of prediction.

[0166] In some embodiments, such as Figure 8 As shown, Figure 8 yes Figure 2 Step 104 in the flowchart is another optional implementation. It predicts the target attack intent corresponding to the initial attack technique chain, including the following steps:

[0167] 104.3.1 When there are multiple attack tactical links for the target, obtain the scenario information corresponding to the target system;

[0168] 104.3.2 Based on scenario information, a corresponding second weight is set for each preset weight factor. The weight factor includes at least historical attack frequency information, attack complexity value, asset sensitivity value, vulnerability exposure face value, and consequence severity value.

[0169] 104.3.3 Based on each weighting factor and the corresponding second weight, the threat score corresponding to each target attack tactical link is evaluated and obtained;

[0170] 104.3.4 Based on the threat score, the attack tactics of each target are sorted and the target attack intent corresponding to a preset number of target attack tactics is predicted and output.

[0171] Steps 104.3.1 to 104.3.4 are described in detail below.

[0172] Contextual information refers to specific data related to the current state and environment of the target system, including system configuration and network topology, which helps in understanding the security posture of the target system under specific circumstances. Weighting factors are key indicators used to assess and quantify attack threats. They typically include information from multiple aspects, such as historical attack frequency, attack complexity, asset sensitivity, vulnerability exposure surface, and consequence severity. These factors help security teams consider different influencing factors when analyzing threats.

[0173] Among these, historical attack frequency information refers to the number or frequency with which a specific attack technique, tactic, or vulnerability has been used or occurred in past attack events. A high attack frequency means the technique or vulnerability is frequently exploited, posing a higher risk and warranting close attention. Attack complexity measures the technical difficulty and resource investment required to implement a particular attack technique or tactic. Higher complexity indicates more challenges for the attacker, making implementation more difficult and potentially corresponding to lower attack risk, and vice versa. Asset sensitivity reflects the importance and sensitivity of the attacked asset, including its data value, scope of impact, and criticality. Highly sensitive assets have greater potential losses and impacts after being attacked. Vulnerability exposure face value describes the degree to which known vulnerabilities in the target system are publicly disclosed or easily exploitable by attackers, such as the extent to which vulnerabilities are widely disclosed or easily scanned and exploited. A larger exposure face value indicates a greater risk. Consequence severity represents the severity of the potential impact or loss after a successful attack, including data breaches, system downtime, and financial losses. Higher severity indicates greater potential harm from the attack.

[0174] The threat score is a quantitative indicator calculated by integrating various weighting factors and their corresponding second weights. It is used to assess the potential threat level of a specific attack tactical link. Furthermore, this application embodiment sorts all potential target attack links based on the threat score and outputs the corresponding target attack intent according to the sorting, so that relevant personnel can focus on the most threatening or most likely attack paths.

[0175] Furthermore, this application embodiment effectively identifies and prioritizes the most threatening attack paths by systematically evaluating and ranking the target attack tactical links, thereby giving priority to the target attack intent corresponding to high-risk paths. At the same time, by predicting the target attack intent under other possibilities, it provides a basis for formulating diversified response strategies, thereby enhancing the system's proactive defense and rapid response capabilities.

[0176] In some embodiments, such as Figure 9 As shown, Figure 9 yes Figure 2 Step 104 in the flowchart is another optional implementation. After predicting the target attack intent corresponding to the initial attack technique chain, it also includes the following steps:

[0177] 104.4.1 Obtain information on the current attack phase of the target system;

[0178] 104.4.2 Input the attack phase information, target attack tactical links and corresponding target attack intentions into the target big model, and output the target system's defense strategy information.

[0179] Steps 104.4.1 to 104.4.2 are described in detail below.

[0180] Among them, attack phase information is used to characterize the specific stage or state that the target system is currently in. For example, attack phase information can indicate that the target system is currently in the initial stage of the attack (such as reconnaissance), the execution stage (such as exploiting vulnerabilities), or the later stage (such as maintaining access or data theft).

[0181] The defense strategy information refers to the specific security protection measures and response plans formulated based on the current attack situation and the characteristics of the target system. These strategies include, but are not limited to, strengthening network monitoring, implementing access control, and updating security patches to reduce the likelihood and impact of a successful attack. Before the attacker achieves its final attack goal, this application embodiment can input attack phase information, target attack tactical links, and corresponding target attack intentions into the target big model, so that the target big model can analyze and infer the most suitable defense measures or strategies based on this information, thereby guiding security personnel to take effective countermeasures.

[0182] To help readers better understand the methodology of this application, such as Figure 10 As shown, Figure 10 This is another optional flowchart of the network attack intent prediction method based on ATT&CK provided in the embodiments of this application. The following is an example of another complete embodiment:

[0183] The prediction method implemented in this application consists of four parts:

[0184] (1) Domain knowledge modeling layer, attack technique and tactic link layer, tactic and intent association layer and attack intent prediction layer. This layer defines a multi-step attack related schema based on the ATT&CK knowledge base, including attack technique and tactic schema, attack steps and attack chain schema, and sets association rules (i.e. attack logic constraint rules, etc., and other rules can be added according to specific circumstances in actual application) to constrain the association relationship between attack techniques and tactics, the association relationship between attack steps and attack chains, thereby supporting the extraction of attack knowledge in a given scenario, reducing the noise of open set recognition, and making the output results more consistent with the domain expression.

[0185] (2) The second part is the attack tactics link layer. This layer uses the target big model and extracts knowledge according to schema constraints and expert rules to form the ATT&CK knowledge base, and injects the initial prompt information into the target big model.

[0186] Specifically, in a target system within a given or hypothetical scenario (such as a network range scenario), firstly, based on the initial attack events captured by the detection device, high-confidence attack events are extracted (or filtered) according to the tactical stages corresponding to the attack techniques to construct the initial attack event chain (e.g., Taaa->Tbbb->?->Tddd, where Taaa, Tbbb, and Tddd all represent attack events); then, through time window constraints (e.g., consecutive events within N minutes) and tactical continuity verification, an incomplete initial attack technique chain containing 2-3 core tactical nodes (e.g., system information discovery (T1082) will be executed after command execution (T1059)) is extracted (e.g., T1059->T1082->? ... >? ->T1003), where “?” indicates a technical gap, which includes at least one speculative attack technique; then, the target big model completes the initial attack technique chain based on the initial prompt information to obtain a complete and reliable time-series target attack technique chain (e.g., several different target attack technique chains such as T1059->T1082->T1558.003->T1003, where T1059, T1082, and T1003 all represent attack techniques); then, the target attack tactical chain corresponding to each target attack technique chain is determined (TAxxx->TAyyy->TAzzz, where TAxxx, TAyyy, and TAzzz all represent attack tactics).

[0187] (3) The third part is the tactic and intent association layer. Based on the semantic information of the tactic layer of the ATT&CK framework, this layer establishes a causal relationship between each tactic in the attack tactic chain output from the previous layer and its preceding or following tactics. By associating the context association field where it is located, the attack sub-intent of each attack tactic is obtained, and then the set of attack sub-intents is obtained.

[0188] Specifically, a process-oriented introduction to multi-step attack detection and intent assessment is provided using one of the target attack tactical links (TAxxx->TAyyy->TAzzz):

[0189] ①The associated context field and subsequent tactic TAyyy corresponding to TAxxx;

[0190] ②The associated context fields of TAyyy and the preceding tactic TAxxx and the following tactic TAyyy;

[0191] ③The associated context fields of TAzzz and the preceding tactic TAyyy and the following tactic TAzzz.

[0192] In this embodiment, ①, ②, and ③ constitute the target attack tactical chain TAxxx->TAyyy->TAzzz. Each attack tactic outputs a tactical sub-intention through the target large model, thereby obtaining the attack sub-intention set {X,Y,Z}. The attack tactical chain TAxxx->TAyyy->TAzzz, the attack sub-intention set {X,Y,Z}, and context information are input into the target large model to obtain updated prompt information. Thus, the interaction effect with the model is gradually improved through repeated iterations of the prompt information in this application embodiment.

[0193] (4) The fourth part is the attack intent prediction layer. This layer inputs the updated prompt information into the target large model and outputs the N most likely target attack intents and the corresponding defense strategy information based on historical attack events and their frequency, so as to help relevant personnel to better adopt relevant defense strategies.

[0194] like Figure 11 As shown, Figure 11 This is a schematic diagram of an optional device module of the network attack intent prediction device based on ATT&CK provided in this application embodiment. The network attack intent prediction device based on ATT&CK may include the following modules 201 to 204:

[0195] The acquisition module 201 is used to capture multiple initial attack events from the target system, extract at least two attack events from the multiple initial attack events, and form an incomplete initial attack technique chain based on the attack techniques adopted by the extracted attack events.

[0196] The initial prompt information module 202 is used to determine the initial technical and tactical information corresponding to each attack technique based on the preset ATT&CK knowledge base, parse each attack event to determine the corresponding initial context information, and obtain the initial prompt information under multi-dimensional semantics based on the initial attack technique link, the initial technical and tactical information and the initial context information.

[0197] The completion module 203 is used to input the initial attack technology link and initial prompt information into the preset target large model to obtain at least one target attack technology link corresponding to the initial attack technology link after completion, and to determine the target attack tactical link to which the target attack technology link belongs based on the ATT&CK knowledge base, wherein the target attack tactical link includes multiple attack tactics.

[0198] The target prediction module 204 is used to determine the set of attack sub-intents of the target attack tactical link, update the initial prompt information according to the set of attack sub-intents to obtain updated prompt information, input the target attack tactical link and the updated prompt information into the target large model, and predict the target attack intent corresponding to the initial attack tactical link.

[0199] This application proposes a network attack intent prediction method and related equipment based on ATT&CK. It captures multiple initial attack events from the target system, extracts at least two attack events from these initial events, and constructs an incomplete initial attack technique chain based on the attack techniques employed by the extracted attack events. Next, it determines the initial tactical information corresponding to each attack technique based on a pre-set ATT&CK knowledge base, parses each attack event to determine the corresponding initial context information, and obtains multi-dimensional semantic initial prompt information based on the initial attack technique chain, initial tactical information, and initial context information. This initial prompt information provides multi-faceted threat risk understanding and response suggestions, enabling the subsequent target large-scale model to complete the initial attack chain based on the initial prompt information. The initial attack technique chain and initial warning information are input into a preset target model to obtain at least one target attack technique chain corresponding to the completed initial attack technique chain. Based on the ATT&CK knowledge base, the target attack tactical chain to which the target attack technique chain belongs is determined. The attack sub-intent set of the target attack tactical chain is determined, and the initial warning information is updated according to the attack sub-intent set to obtain updated warning information. The target attack technique chain and updated warning information are input into the target model to predict the target attack intent corresponding to the initial attack technique chain. In this way, the initial warning information is dynamically updated to obtain updated warning information, which helps to identify the attacker's potential strategies and next actions in a timely manner and improves the accuracy of the final predicted target attack intent.

[0200] The specific implementation of the network attack intent prediction device based on ATT&CK is basically the same as the specific implementation of the network attack intent prediction method based on ATT&CK described above, and will not be repeated here.

[0201] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned network attack intent prediction method based on ATT&CK. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0202] like Figure 12 As shown, Figure 12 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. The electronic device includes:

[0203] The processor 301 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0204] The memory 302 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 302 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 302 and is called and executed by the processor 301 using the ATT&CK-based network attack intent prediction method of the embodiments of this application.

[0205] Input / output interface 303 is used to implement information input and output;

[0206] The communication interface 304 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0207] Bus 305 transmits information between various components of the device (e.g., processor 301, memory 302, input / output interface 303, and communication interface 304);

[0208] The processor 301, memory 302, input / output interface 303, and communication interface 304 are connected to each other within the device via bus 305.

[0209] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described ATT&CK-based network attack intent prediction method.

[0210] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0211] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0212] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0213] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0214] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0215] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0216] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0217] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0218] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0219] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0220] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0221] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for predicting network attack intent based on ATT&CK, characterized in that, include: Multiple initial attack events are captured from the target system, and at least two attack events are extracted from the multiple initial attack events. An incomplete initial attack technique chain is formed based on the attack techniques adopted by the extracted attack events. Based on the preset ATT&CK knowledge base, the initial technical and tactical information corresponding to each of the attack techniques is determined, the initial context information corresponding to each of the attack events is determined by parsing, and the initial prompt information under multi-dimensional semantics is obtained based on the initial attack technique link, the initial technical and tactical information and the initial context information. The initial attack technology link and the initial prompt information are input into a preset target large model to obtain at least one target attack technology link corresponding to the initial attack technology link after it is completed. The target attack tactical link to which the target attack technology link belongs is determined based on the ATT&CK knowledge base. The attack sub-intent set of the target attack tactical link is determined, and the initial prompt information is updated according to the attack sub-intent set to obtain updated prompt information. The target attack tactical link and the updated prompt information are input into the target large model to predict the target attack intent corresponding to the initial attack tactical link.

2. The network attack intent prediction method based on ATT&CK according to claim 1, characterized in that, The capture of multiple initial attack events from the target system includes: Capture basic attribute information and associated attribute information belonging to the same attack identifier from the target system. The basic attribute information includes at least descriptive information and attack occurrence time information. The associated attribute information includes at least attack technique information, affected asset information, and attack status information. Based on the basic attribute information and the associated attribute information, the initial attack event under the hierarchical data structure is captured.

3. The network attack intent prediction method based on ATT&CK according to claim 2, characterized in that, The step of extracting at least two attack events from a plurality of initial attack events, and forming an incomplete initial attack technique chain based on the attack techniques employed by the extracted attack events, includes: Different first weights are assigned to the basic attribute information and the associated attribute information respectively, and the defense coverage of each initial attack event is evaluated based on the first weights to obtain the corresponding confidence value; Based on the ATT&CK knowledge base, multiple initial attack events are classified into different tactical stages, and at least two attack events are extracted from at least two tactical stages based on the confidence value. Based on the attack occurrence time information of the attack event, the corresponding attack techniques are sequentially connected to obtain an incomplete initial attack technique link.

4. The network attack intent prediction method based on ATT&CK according to claim 1, characterized in that, The step of inputting the initial attack technique link and the initial prompt information into a preset target large model to obtain at least one target attack technique link corresponding to the completed initial attack technique link includes: The initial attack technique chain and the initial prompt information are input into the preset target large model, and predefined attack logic constraint rules are obtained; Based on the attack logic constraint rules, at least one technical breakpoint in the initial attack technique chain is identified. Based on the initial prompt information, the speculative attack technique associated with the technical gap is determined, and the speculative attack technique is inserted into the technical gap to obtain the target attack technique link corresponding to the completed initial attack technique link.

5. The network attack intent prediction method based on ATT&CK according to claim 4, characterized in that, The target attack tactical chain includes multiple attack tactics; The determination of the set of attack sub-intents for the target attack tactical link includes: Identify the speculative attack event corresponding to the speculative attack technique, and parse the speculative attack event to determine the corresponding speculative context information; Extract the first key field corresponding to the current attack tactic from the initial context information or the inferred context information corresponding to any of the attack tactic, and determine at least one adjacent attack tactic corresponding to the current attack tactic; The second key field corresponding to the adjacent attack tactic is extracted from the initial context information or the inferred context information corresponding to the adjacent attack tactic; Based on the first key field and the second key field, determine the context association field corresponding to the current attack tactic; Based on the adjacent attack tactics and the context association field, the attack sub-intention corresponding to the current attack technique is determined, and the attack sub-intentions of all the attack techniques are integrated to obtain the attack sub-intention set.

6. The network attack intent prediction method based on ATT&CK according to claim 5, characterized in that, The step of updating the initial prompt information according to the attack sub-intent set to obtain updated prompt information includes: Based on the ATT&CK knowledge base, the updated tactical information corresponding to the speculative attack technique is determined; The initial prompt information is updated based on the target attack tactical link, the inferred context information, the updated tactical information, and the attack sub-intent set to obtain the updated prompt information under multi-dimensional semantics.

7. The network attack intent prediction method based on ATT&CK according to claim 1, characterized in that, The prediction yields the target attack intent corresponding to the initial attack technique chain, including: When there are multiple attack tactical links for the target, obtain the scenario information corresponding to the target system; Based on the scenario information, a corresponding second weight is set for each preset weight factor, wherein the weight factor includes at least historical attack frequency information, attack complexity value, asset sensitivity value, vulnerability exposure face value and consequence severity value. Based on each of the weighting factors and the corresponding second weight, the threat score corresponding to each of the target attack tactical links is evaluated and obtained. Based on the threat score, each of the target attack tactical links is sorted, and the target attack intent corresponding to a preset number of the target attack tactical links is predicted and output.

8. The network attack intent prediction method based on ATT&CK according to claim 1, characterized in that, After the target attack intent corresponding to the initial attack technique chain is predicted, the method further includes: Obtain information on the current attack phase of the target system; The attack phase information, the target attack tactical link, and the corresponding target attack intent are input into the target big model, and the defense strategy information of the target system is output.

9. A network attack intent prediction device based on ATT&CK, characterized in that, include: The acquisition module is used to capture multiple initial attack events from the target system, extract at least two attack events from the multiple initial attack events, and form an incomplete initial attack technique chain based on the attack techniques adopted by the extracted attack events. The initial prompt information module is used to determine the initial technical and tactical information corresponding to each of the attack techniques based on the preset ATT&CK knowledge base, parse each of the attack events to determine the corresponding initial context information, and obtain the initial prompt information under multi-dimensional semantics based on the initial attack technique link, the initial technical and tactical information and the initial context information. The completion module is used to input the initial attack technology link and the initial prompt information into a preset target large model to obtain at least one target attack technology link corresponding to the initial attack technology link after completion, and to determine the target attack tactical link to which the target attack technology link belongs based on the ATT&CK knowledge base, wherein the target attack tactical link includes multiple attack tactics; The target prediction module is used to determine the set of attack sub-intents of the target attack tactical link, update the initial prompt information according to the set of attack sub-intents to obtain updated prompt information, input the target attack tactical link and the updated prompt information into the target large model, and predict the target attack intent corresponding to the initial attack tactical link.

10. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the network attack intent prediction method based on any one of claims 1 to 8.

11. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the network attack intent prediction method based on ATT&CK as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Behavior prediction method and device, electronic equipment and computer readable storage medium

    CN114301699A

  • Network attack prediction method and system based on attack portrait

    CN116938527A