Response processing method and system for network security event
Through feature extraction and hidden Markov model analysis of network traffic data, the attack chain is reconstructed and a dynamic response strategy is generated, which solves the problems of insufficient behavior correlation capture and inaccurate intent inference in existing technologies and achieves efficient network security incident response.
Patent Information
- Application Number
- CN202510977892.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-16
- Publication Date
- 2025-09-16
AI Technical Summary
Existing technologies have difficulty capturing behavioral correlations in complex attack scenarios, have low attack chain reconstruction accuracy, and inaccurate intent inference. They are unable to respond to new attacks in real time, resulting in delayed responses.
By acquiring network traffic data, performing feature extraction and temporal behavior clustering, the hidden Markov model is used to calculate the causal relationship confidence, reconstruct the attack chain, generate a dynamic response strategy, and execute it using a streaming processing engine.
It improves detection accuracy and response efficiency in complex attack scenarios, can respond to new threats in a timely manner, and ensure network security and stability.
Smart Images

Figure CN120658497A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and system for responding to network security events. Background Art
[0002] Cybersecurity incident response is a core area of information system security. It involves timely identifying and containing threats to minimize the damage to critical infrastructure and data. As a key component of incident response, threat behavior pattern recognition directly impacts the accuracy of attack intent assessments and is an indispensable technical pillar of the defense system.
[0003] In network security defense, traditional methods primarily rely on static time windows and fixed rules to analyze network traffic, making them incapable of handling scenarios where attackers employ time-delay strategies to disperse their attacks. The limitations of these traditional methods include the inability to capture dispersed attack behaviors over long time spans, resulting in fragmented attack chains and difficulty capturing behavioral correlations. Most methods use simple thresholds to determine causality, leading to high false positive rates in the presence of noise. Furthermore, existing technologies lack dynamic analysis of attack chain topology, making it difficult to match advanced threat models and resulting in inaccurate inferences of attack intent. Furthermore, most existing technologies rely on manual strategy adjustments, making them incapable of responding to new attacks in real time and resulting in delayed responses. Summary of the Invention
[0004] In order to solve the above technical problems, the present invention provides a response and processing method and system for network security incidents, which can solve the problems of insufficient behavior correlation capture, low attack chain reconstruction accuracy and poor intent inference reliability in existing technologies in complex attack scenarios, and achieve the technical effect of improving detection accuracy and response efficiency in complex attack scenarios.
[0005] In a first aspect, the present invention provides a method for responding to a network security incident, the method comprising: Acquire network traffic data, perform feature extraction and time series behavior clustering on the network traffic data, and obtain behavior segments and corresponding time series features; Calculating the confidence of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the temporal features; Perform attack chain reconstruction and critical path analysis based on the behavior fragments and the causal relationship confidence to obtain the attack critical path; Inputting the attack key path into a preset threat pattern library for threat matching to obtain an attack intention prediction result, wherein the attack intention prediction result includes the attack intention type and the attack target distribution probability; A dynamic response strategy is generated according to the attack intention prediction result, and a streaming processing engine is used to execute the dynamic response strategy.
[0006] Furthermore, the step of performing feature extraction and time series behavior clustering on the network traffic data to obtain behavior segments and corresponding time series features includes: Using a dynamic time warping algorithm to perform time series alignment on the network traffic data to obtain initial behavior time series data; Performing abnormal interval detection on the initial behavior time series data to obtain behavior time series data containing abnormal marker points; Extracting features from the behavior time series data to obtain time series features, where the time series features include behavior frequency, interval mean, and time entropy; Hierarchical clustering is used to cluster the time series features to obtain clustering results, which include different types of behavior segments and corresponding time series features.
[0007] Furthermore, the step of calculating the confidence of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the time series features includes: Define hidden states according to normal traffic and attack traffic, and use the time series features as observation states to construct a hidden Markov model; Performing parameter learning on the hidden Markov model through a forward-backward algorithm to obtain a transition probability matrix and an emission probability matrix; The causal relationship confidence between adjacent behavior segments is calculated based on the transition probability matrix and the emission probability matrix.
[0008] Furthermore, after the step of calculating the causal relationship confidence between adjacent behavior segments according to the transition probability matrix and the emission probability matrix, the method further includes: Determine whether the causal relationship confidence is less than a preset initial confidence. If so, optimize the causal relationship confidence using the Bayesian formula based on the context factor to obtain an optimized causal relationship confidence.
[0009] Furthermore, the step of performing attack chain reconstruction and critical path analysis based on the behavior fragments and the causal relationship confidence to obtain the attack critical path includes: Using the behavior fragments as nodes and the causal relationship confidence as edge weights, constructing an attack chain topology structure based on the behavior graph; Calculating the importance score of each node in the attack chain topology structure using a web page ranking algorithm, and identifying key nodes based on the importance score; According to the key nodes, a community detection algorithm is used to divide the attack chain topology structure into attack subgraphs to obtain the attack key path.
[0010] Furthermore, the step of inputting the attack critical path into a preset threat pattern library for threat matching to obtain an attack intention prediction result includes: Mapping nodes in the attack critical path into low-dimensional vectors using graph embedding technology, and calculating similarities between the low-dimensional vectors and pre-set vectors in a threat pattern library; Classifying the attack intentions according to the similarity to obtain the attack intention type corresponding to the attack critical path; The attack critical path is input into a preset attack target prediction model to obtain the attack target distribution probability, and the attack target prediction model is constructed based on a long short-term memory neural network.
[0011] Furthermore, the step of generating a dynamic response strategy according to the attack intention prediction result includes: Obtaining a response action based on the attack intention prediction result and a preset intention-action mapping rule; generating a response priority based on the attack intention prediction result and the importance score of the key node; A dynamic response strategy is generated according to the response action and the response priority.
[0012] Furthermore, the step of using a stream processing engine to execute the dynamic response strategy includes: Based on the sliding window mechanism, the behavior frequency of the real-time traffic data in the window is counted, and whether to trigger the response action is determined according to the behavior frequency; In response to triggering the response action, the response action is executed according to the response priority.
[0013] Furthermore, after the step of using the stream processing engine to execute the dynamic response strategy, the method further includes: Acquire real-time traffic data, perform incremental feature extraction on the real-time traffic data, and add the extracted incremental features to a feature library; An execution feedback result of the dynamic response strategy is obtained, and based on the execution feedback result and the feature library, a FTRL algorithm is used to update and incrementally train model parameters.
[0014] In a second aspect, the present invention provides a network security incident response processing system, the system comprising: A segmentation module is used to obtain network traffic data, perform feature extraction and temporal behavior clustering on the network traffic data, and obtain behavior segments and corresponding temporal features; A causal analysis module, configured to calculate the confidence of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the temporal features; An attack chain reconstruction module, configured to perform attack chain reconstruction and key path analysis based on the behavior fragments and the causal relationship confidence levels to obtain a key attack path; An attack intention prediction module is used to input the attack key path into a preset threat pattern library for threat matching to obtain an attack intention prediction result, wherein the attack intention prediction result includes the attack intention type and the attack target distribution probability; The dynamic response module is used to generate a dynamic response strategy according to the attack intention prediction result, and use a stream processing engine to execute the dynamic response strategy.
[0015] The present invention provides a response processing method and system for network security incidents. Through dynamic time regularization and adaptive window mechanism, the present invention can eliminate the time delay interference deliberately introduced by attackers and improve the correlation of behaviors; through the hidden Markov model to quantify behavioral correlations and introduce context factors for optimization, it can effectively reduce causal misjudgment; through the attack chain reconstruction method, it can accurately locate real threats; through dynamic strategy generation, streaming computing engine and online learning, it realizes a closed loop from attack detection to automatic defense, and can respond to new threats in a timely manner. The present invention can significantly improve the attack detection accuracy and defense response efficiency in complex attack scenarios, and provide an adaptive and reliable technical solution for network security protection, thereby ensuring the security and stability of network operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 1 is a flow chart of a method for responding to and processing network security incidents according to an embodiment of the present invention; Figure 2 It is a structural diagram of a network security incident response and processing system in an embodiment of the present invention. DETAILED DESCRIPTION
[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0018] See also Figure 1 The first embodiment of the present invention provides a method for responding to a network security incident, which includes steps S10 to S50: Step S10: acquiring network traffic data, performing feature extraction and time series behavior clustering on the network traffic data, and obtaining behavior segments and corresponding time series features; Step S20, calculating the confidence of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the temporal features; Step S30: performing attack chain reconstruction and key path analysis based on the behavior fragments and the causal relationship confidence to obtain the attack key path; Step S40: inputting the attack critical path into a preset threat pattern library for threat matching to obtain an attack intention prediction result, wherein the attack intention prediction result includes the attack intention type and the attack target distribution probability; Step S50: generating a dynamic response strategy based on the attack intention prediction result, and executing the dynamic response strategy using a stream processing engine.
[0019] In the present invention, the network traffic data is first analyzed to extract traffic behavior segments. The specific steps include: Using a dynamic time warping algorithm to perform time series alignment on the network traffic data to obtain initial behavior time series data; Performing abnormal interval detection on the initial behavior time series data to obtain behavior time series data containing abnormal marking points; Extracting features from the behavior time series data to obtain time series features, wherein the time series features include behavior frequency, interval mean, and time entropy; Hierarchical clustering is used to cluster the time series features to obtain a clustering result, which includes behavior segments and corresponding time series features.
[0020] In this embodiment, network traffic data is first aligned based on dynamic time windows. This data includes timestamps, protocol types, source / destination IP addresses, and behavior types (e.g., login, download, upload). The purpose of this alignment is to eliminate time delays intentionally introduced by attackers and align the time series of different behaviors. In this embodiment, dynamic time warping (DTW) is used to align the time series. By minimizing the cumulative distance between two sequences, the optimal alignment path is found.
[0021] Then, a sliding window mechanism is used to detect abnormal intervals in the time series data. In this embodiment, an adaptive sliding window mechanism can be used, or the window size can be preset in advance. When an adaptive sliding window mechanism is used, the window size is dynamically adjusted according to the frequency of the behavior. For high-frequency behavior, the window size is reduced, and for low-frequency behavior, the window size is increased. The adjustment formula is: Where W represents the window size, α and β are preset empirical parameters, and S represents the behavior frequency of different behavior types.
[0022] The Z-score of the behavior interval within the window is then calculated. By quantifying the degree of interval deviation, anomaly determination is performed. For example, when |Z| exceeds the threshold (e.g., |Z| > 3), it is marked as an abnormal interval. The anomaly type is determined based on the traffic before and after the interval, such as an extended interval or burst traffic. Finally, behavioral time series data containing abnormal markers is obtained. The abnormal markers include timestamps and anomaly types.
[0023] After obtaining the aligned behavioral time series data, time series features are extracted through time series feature engineering, including behavior frequency (the number of behaviors per unit time), interval mean / variance (the distribution of time intervals), and time entropy (a measure of behavior randomness). The time entropy H can be expressed as: Where p(t) represents the probability of occurrence of time interval t.
[0024] A hierarchical clustering method is then used to cluster the temporal features. Specifically, a similarity matrix of the behavioral segments is first constructed based on the DTW distance. The average linkage method is then used to merge the clusters with the smallest distance to generate a dendrogram. Finally, pruning optimization is performed based on the silhouette coefficient, the optimal number of clusters is selected, and redundant groups are merged to obtain the type classification of the behavioral segments (i.e., clustering results, such as the login-download group and the abnormal upload group) and the temporal feature vectors corresponding to each type of behavioral segment (i.e., the feature matrix of each cluster).
[0025] In this embodiment, the original network traffic data is processed by DTW and sliding windows, which can eliminate the time delay interference intentionally introduced by the attacker, thereby improving the correlation of behaviors.
[0026] For the clustered behavior segments and time series feature vectors, this embodiment uses a hidden Markov model to calculate the confidence level of the causal relationship between adjacent behavior segments. The specific steps include: Define hidden states according to normal traffic and attack traffic, and use the time series features as observation states to construct a hidden Markov model; Performing parameter learning on the hidden Markov model through a forward-backward algorithm to obtain a transition probability matrix and an emission probability matrix; The confidence levels of causal relationships between adjacent behavior segments are calculated based on the transition probability matrix and the emission probability matrix.
[0027] In this embodiment, the confidence level of the causal relationship between adjacent behavior segments is calculated using a hidden Markov model (HMM). Specifically, the hidden state is defined based on normal traffic and attack traffic, and the observation state is defined based on the temporal characteristics of the behavior segments. A forward-backward algorithm is used to learn the parameters of the observation state sequence to obtain the transition probability matrix T and the emission probability matrix E. The probability π of the hidden state is initialized based on the probability of being in each state at the beginning of the observation sequence, thereby obtaining the HMM model λ: Based on the above HMM model λ, calculate the causal confidence P(B|A): Where count(A) represents the number of times behavior segment A appears, and count(A→B) represents the number of times behavior segment A is followed by behavior segment B.
[0028] The causal confidence can be used to characterize the causal link strength between behavior fragment A and behavior fragment B.
[0029] Since network fluctuations may cause network delays or packet loss, which may affect the causal relationship between behavior segments, in order to further improve the calculation accuracy of the causal relationship confidence, in a preferred embodiment, the present invention introduces a context factor to correct the causal relationship confidence calculated based on the HMM model. The following takes the user behavior sequence including login, page browsing and form submission as an example to illustrate the correction steps. It is assumed that by analyzing historical traffic, it can be determined that 90% of the sequences after login are connected to the browsing page, that is, the causal link strength between login and browsing pages is high. Therefore, the initial confidence is set to 0.9. If the calculated causal relationship confidence between login and browsing pages is less than the initial confidence, it may be because the user was interrupted by other tasks after login. The context factor may be the interruption duration or network delay, etc. Then, the context factor probability is set according to the context factor C, and the causal relationship confidence is optimized using the Bayesian formula: Where, represents the optimized causal relationship confidence, represents the context factor probability, Indicates the causal link strength between behavior segment A and context factor C. The formula is calculated.
[0030] In this embodiment, the introduction of contextual factors can better reflect the interference in actual scenarios. By constructing an HMM model and optimizing causal confidence, causal misjudgment is reduced and the analysis accuracy of the causal relationship between behavioral segments is improved.
[0031] After obtaining the behavior fragments and the causal relationships between them, we can reconstruct the attack chain to extract high-frequency attack paths. The specific steps include: Using the behavior fragments as nodes and the causal relationship confidence as edge weights, constructing an attack chain topology structure based on the behavior graph; Calculating the importance score of each node in the attack chain topology structure using a web page ranking algorithm, and identifying key nodes based on the importance score; According to the key nodes, a community detection algorithm is used to divide the attack chain topology structure into attack subgraphs to obtain the attack key path.
[0032] In this embodiment, a behavior graph is constructed with behavior fragments as nodes and causal confidence as edge weights, thereby obtaining the topological structure of the power chain; then, the importance score of each node in the topological structure, that is, each behavior fragment, is calculated through the PageRank algorithm, and the importance of the node is measured by the importance score. For example, the node with an importance score greater than a threshold is used to identify the key node, which can be understood as a behavior fragment that is vulnerable to attack.
[0033] After obtaining the attack chain topology and key nodes, a community detection algorithm is used to partition the topology to obtain attack subgraphs. Attack subgraphs can be interpreted as different attack types, such as lateral movement and data theft. High-frequency attack paths are extracted from the attack subgraphs to obtain the key attack paths.
[0034] Through the attack chain reconstruction method of this embodiment, the key attack path can be accurately extracted, thereby providing accurate input data for subsequent attack intent analysis and defense dynamic response.
[0035] After extracting the attack key path, the attack intent is predicted by inputting the attack key path into the threat pattern library for threat matching. The specific steps include: Mapping nodes in the attack critical path into low-dimensional vectors using graph embedding technology, and calculating similarities between the low-dimensional vectors and pre-set vectors in the threat pattern library; Classifying the attack intentions according to the similarity to obtain the attack intention type corresponding to the attack critical path; The attack critical path is input into a preset attack target prediction model to obtain the attack target distribution probability, and the attack target prediction model is constructed based on a long short-term memory neural network.
[0036] In this embodiment, the attack critical path plays a core role in threat matching and attack intent inference. Specifically, the attack critical path is input into a preset threat pattern library. The threat pattern library is built based on the ATT&CK framework, a comprehensive cybersecurity knowledge base used to understand and classify attacker behavior. The attack intent type corresponding to the attack critical path is obtained by matching it with known attack technique vectors pre-stored in the threat pattern library. During threat matching, graph embedding techniques such as Node2Vec are used to map nodes in the critical path into low-dimensional vectors. The similarity between these vectors and the vectors in the threat pattern library is then calculated. This similarity can be measured using similarity metrics such as cosine similarity or Euclidean distance. To reduce computational complexity, a random walk strategy (balancing breadth-first and depth-first approaches) can be used to sample the vectors before similarity matching. The sampled vectors are then similarly matched against the stored vectors. When the calculated similarity exceeds a similarity threshold, the attack intent of the attack critical path is determined. For example, when the similarity between the key path "login → abnormal download → external connection" and T1048 (data exfiltration) in the ATT&CK framework reaches 0.9, and the similarity threshold is 0.8, the attack intention is determined to be data theft.
[0037] After predicting the attack intention, the attack target of the next stage can also be predicted based on the attack critical path. In this embodiment, since the critical path provides the attacker's staged behavior sequence (such as lateral movement → privilege escalation → data operation), the attack target prediction model constructed based on the long short-term memory neural network LSTM is used as a time series input. The attack target prediction model can predict the attack target of the next stage based on the current attack critical path. For example, if the attack intention of the current critical path is lateral movement, the probability that the attack target of the next stage is privilege escalation predicted by the attack target prediction model is 80%, thereby obtaining the distribution probability of the attack target.
[0038] In this embodiment, by performing threat pattern matching and attack intent prediction on the critical attack path, the real threat can be located more accurately, and false alarms of attacks can be reduced, thereby improving the response efficiency and defense effectiveness of subsequent defense responses.
[0039] After predicting the attack intent and the probability of attack target distribution, a dynamic response strategy can be generated and executed using a stream processing engine. In a preferred embodiment, the dynamic response strategy can be generated based on a preset rule base, and the specific steps include: Obtaining a response action based on the attack intention prediction result and a preset intention-action mapping rule; generating a response priority based on the attack intention prediction result and the importance score of the key node; A dynamic response strategy is generated according to the response action and the response priority.
[0040] In this embodiment, a rule base is pre-established, which stores mapping rules between attack intentions and response actions. For example, the action corresponding to data leakage intention is to trigger traffic mirroring and start sensitive data filtering; the action corresponding to Dos intention is to limit the source IP bandwidth and enable traffic cleaning; the action corresponding to lateral movement intention is to block access to high-risk ports and mark suspicious IPs to add to the blacklist.
[0041] According to the predicted attack intent type, the corresponding response action is matched from the rule library. At the same time, according to the distribution probability of the next attack target, the corresponding defense action is set. For example, when the next attack target is privilege escalation, a response action such as privilege verification protection can be added. When there are multiple response actions, this embodiment sorts each response action by response priority, wherein the response priority is obtained by weighted summation based on the importance score of the key nodes in the attack critical path and the probability of the attack intent. The probability of the attack intent here is the similarity obtained when predicting the attack intent and the distribution probability output by the attack target prediction model. The response actions are sorted according to the response priority to obtain a dynamic response strategy. The strategy is an instruction set in JSON format.
[0042] After obtaining the dynamic response policies, this embodiment uses a stream processing engine to execute them. A stream processing engine is a technology used to process continuous data streams in real time. It can perform computations and processing directly as data is generated or received, without waiting for the entire dataset to be prepared. This real-time nature enables stream processing systems to quickly respond to events and support real-time decision-making. Preferably, this embodiment uses the stream processing engine Apache Flink to execute the dynamic response policies. This engine offers high throughput and low latency, making it suitable for a variety of time-sensitive applications. When using the stream processing engine Apache Flink to execute dynamic response policies, its input is real-time traffic data (Kafka stream) and dynamic response policies (JSON). The processing logic is window-triggered, assuming a 10-second window size and a 2-second sliding step. The frequency of behavior within the window is counted, and then the action execution condition is determined. For example, for high-frequency requests, if the number of requests from the same source IP within 10 seconds exceeds 100, rate limiting is triggered. For sensitive data hits, filtering is triggered by matching regular expressions on the payload. The engine also performs state management, such as maintaining IP blacklist status and blocking all traffic from blacklisted IPs. The stream processing engine executes actions in real time by calling the API, and records the triggered actions and defense effects in real time to generate response logs for subsequent auditing and analysis.
[0043] After the execution of the dynamic response strategy is completed, this embodiment also provides a closed-loop optimization method to adapt to new threats through online learning and model updates. Specifically, incremental feature extraction is performed on the latest real-time traffic data to extract new behavioral features such as new attack patterns, and the feature library used for training is updated. Then, based on the feedback results of the execution of the dynamic response strategy, such as false positives or missed positives, and combined with the newly added features, the FTRL algorithm is used to adjust the model parameters, and the model is incrementally trained using the newly added features. The model here includes a hidden Markov model and an LSTM-based attack target prediction model. The online learning and model update method provided by this embodiment can effectively improve the prediction accuracy, thereby enabling timely and effective response to new threats, further improving the security of network operation.
[0044] This embodiment provides a response and processing method for network security incidents. The present invention can eliminate the time delay interference deliberately introduced by the attacker and improve the correlation of behaviors through dynamic time regularization and adaptive window mechanism; quantify the behavioral correlation through the hidden Markov model and introduce context factors for optimization, which can effectively reduce causal misjudgment and improve the analysis accuracy of the causal relationship between behavioral segments; through the attack chain reconstruction method, it can accurately locate the real threat, thereby improving the response efficiency and defense effect of subsequent defense response; through dynamic strategy generation, streaming computing engine and online learning, a closed loop from attack detection to automatic defense is realized, and it can respond to new threats in a timely manner. The present invention can significantly improve the attack detection accuracy and defense response efficiency in complex attack scenarios, and provide an adaptive and reliable technical solution for network security protection, thereby ensuring the security and stability of network operation.
[0045] See also Figure 2 Based on the same inventive concept, a second embodiment of the present invention provides a network security incident response and processing system, including: The segmentation module 10 is used to obtain network traffic data, perform feature extraction and temporal behavior clustering on the network traffic data, and obtain behavior segments and corresponding temporal features; A causal analysis module 20 is configured to calculate the confidence level of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the temporal features; An attack chain reconstruction module 30 is configured to perform attack chain reconstruction and key path analysis based on the behavior fragments and the causal relationship confidence levels to obtain a key attack path; An attack intention prediction module 40 is configured to input the attack key path into a preset threat pattern library for threat matching to obtain an attack intention prediction result, wherein the attack intention prediction result includes the attack intention type and the attack target distribution probability; The dynamic response module 50 is configured to generate a dynamic response strategy based on the attack intention prediction result, and execute the dynamic response strategy using a stream processing engine.
[0046] The technical features and technical effects of the network security incident response and processing system proposed in the embodiment of the present invention are the same as those of the method proposed in the embodiment of the present invention, and will not be described in detail here. The various modules in the above-mentioned network security incident response and processing system can be implemented in whole or in part by software, hardware, and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0047] In summary, an embodiment of the present invention proposes a method and system for responding to network security incidents. The method obtains network traffic data, performs feature extraction and time-series behavior clustering on the network traffic data, and obtains behavior segments and corresponding time-series features; based on the behavior segments and the time-series features, a hidden Markov model is used to calculate the causal relationship confidence between adjacent behavior segments; based on the behavior segments and the causal relationship confidence, attack chain reconstruction and critical path analysis are performed to obtain an attack critical path; the attack critical path is input into a preset threat pattern library for threat matching to obtain an attack intention prediction result, which includes the attack intention type and the attack target distribution probability; based on the attack intention prediction result, a dynamic response strategy is generated, and a streaming processing engine is used to execute the dynamic response strategy. The present invention can eliminate the time delay interference deliberately introduced by the attacker and improve the correlation of behaviors through dynamic time regularization and adaptive window mechanism; quantify the behavioral correlation through the hidden Markov model and introduce context factors for optimization, which can effectively reduce causal misjudgment and improve the analysis accuracy of the causal relationship between behavioral segments; through the attack chain reconstruction method, it can accurately locate the real threat, thereby improving the response efficiency and defense effect of subsequent defense response; through dynamic strategy generation, streaming computing engine and online learning, it realizes a closed loop from attack detection to automatic defense, and can respond to new threats in a timely manner. The present invention can significantly improve the attack detection accuracy and defense response efficiency in complex attack scenarios, and provide an adaptive and reliable technical solution for network security protection, thereby ensuring the security and stability of network operation.
[0048] Each embodiment in this specification is described in a progressive manner, and the same or similar parts of each embodiment can be directly referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. It should be noted that the various technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0049] The above-described embodiments merely represent several preferred implementations of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art could make several improvements and substitutions without departing from the technical principles of the present invention, and these improvements and substitutions should also be considered within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be based on the scope of protection of the claims.
Claims
1. A method for responding to network security incidents, characterized in that: include: Acquire network traffic data, perform feature extraction and time series behavior clustering on the network traffic data, and obtain behavior segments and corresponding time series features; Calculating the confidence of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the temporal features; Perform attack chain reconstruction and critical path analysis based on the behavior fragments and the causal relationship confidence to obtain the attack critical path; Inputting the attack key path into a preset threat pattern library for threat matching to obtain an attack intention prediction result, wherein the attack intention prediction result includes the attack intention type and the attack target distribution probability; A dynamic response strategy is generated according to the attack intention prediction result, and a streaming processing engine is used to execute the dynamic response strategy.
2. The method for responding to a network security incident according to claim 1, wherein: The step of performing feature extraction and time series behavior clustering on the network traffic data to obtain behavior segments and corresponding time series features includes: Using a dynamic time warping algorithm to perform time series alignment on the network traffic data to obtain initial behavior time series data; Performing abnormal interval detection on the initial behavior time series data to obtain behavior time series data containing abnormal marker points; Extracting features from the behavior time series data to obtain time series features, where the time series features include behavior frequency, interval mean, and time entropy; Hierarchical clustering is used to cluster the time series features to obtain clustering results, which include different types of behavior segments and corresponding time series features.
3. The method for responding to a network security incident according to claim 1, wherein: The step of calculating the confidence of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the time series features includes: Define hidden states according to normal traffic and attack traffic, and use the time series features as observation states to construct a hidden Markov model; Performing parameter learning on the hidden Markov model through a forward-backward algorithm to obtain a transition probability matrix and an emission probability matrix; The causal relationship confidence between adjacent behavior segments is calculated based on the transition probability matrix and the emission probability matrix.
4. The method for responding to a network security incident according to claim 3, wherein: After the step of calculating the confidence of the causal relationship between adjacent behavior segments according to the transition probability matrix and the emission probability matrix, the method further includes: Determine whether the causal relationship confidence is less than a preset initial confidence. If so, optimize the causal relationship confidence using the Bayesian formula based on the context factor to obtain an optimized causal relationship confidence.
5. The method for responding to a network security incident according to claim 1, wherein: The step of performing attack chain reconstruction and key path analysis based on the behavior fragments and the causal relationship confidence to obtain the attack key path includes: Using the behavior fragments as nodes and the causal relationship confidence as edge weights, constructing an attack chain topology structure based on the behavior graph; Calculating the importance score of each node in the attack chain topology structure using a web page ranking algorithm, and identifying key nodes based on the importance score; According to the key nodes, a community detection algorithm is used to divide the attack chain topology structure into attack subgraphs to obtain the attack key path.
6. The method for responding to a network security incident according to claim 1, wherein: The step of inputting the attack key path into a preset threat pattern library for threat matching to obtain an attack intention prediction result includes: Mapping nodes in the attack critical path into low-dimensional vectors using graph embedding technology, and calculating similarities between the low-dimensional vectors and pre-set vectors in the threat pattern library; Classifying the attack intentions according to the similarity to obtain the attack intention type corresponding to the attack critical path; The attack critical path is input into a preset attack target prediction model to obtain the attack target distribution probability, and the attack target prediction model is constructed based on a long short-term memory neural network.
7. The method for responding to a network security incident according to claim 5, wherein: The step of generating a dynamic response strategy according to the attack intention prediction result includes: Obtaining a response action based on the attack intention prediction result and a preset intention-action mapping rule; generating a response priority based on the attack intention prediction result and the importance score of the key node; A dynamic response strategy is generated according to the response action and the response priority.
8. The method for responding to a network security incident according to claim 7, wherein: The step of using a stream processing engine to execute the dynamic response strategy includes: Based on the sliding window mechanism, the behavior frequency of the real-time traffic data in the window is counted, and whether to trigger the response action is determined according to the behavior frequency; In response to triggering the response action, the response action is executed according to the response priority.
9. The method for responding to a network security incident according to claim 5, wherein: After the step of using the stream processing engine to execute the dynamic response strategy, the method further includes: Acquire real-time traffic data, perform incremental feature extraction on the real-time traffic data, and add the extracted incremental features to a feature library; An execution feedback result of the dynamic response strategy is obtained, and based on the execution feedback result and the feature library, a FTRL algorithm is used to update and incrementally train model parameters.
10. A network security incident response processing system, characterized in that: include: A segmentation module is used to obtain network traffic data, perform feature extraction and temporal behavior clustering on the network traffic data, and obtain behavior segments and corresponding temporal features; A causal analysis module, configured to calculate the confidence of the causal relationship between adjacent behavior segments using a hidden Markov model based on the behavior segments and the temporal features; An attack chain reconstruction module, configured to perform attack chain reconstruction and key path analysis based on the behavior fragments and the causal relationship confidence levels to obtain a key attack path; An attack intention prediction module is used to input the attack key path into a preset threat pattern library for threat matching to obtain an attack intention prediction result, wherein the attack intention prediction result includes the attack intention type and the attack target distribution probability; The dynamic response module is used to generate a dynamic response strategy according to the attack intention prediction result, and use a stream processing engine to execute the dynamic response strategy.
Citation Information
Patent Citations
Markov signal game-based moving target defense strategy selection method and equipment
CN110460572A
Threat intelligence detection method, device, equipment and medium based on honeypot trapping
CN119766493A
Security operation and maintenance management method and system based on network security event
CN119835080A
Network security defense method and system based on incremental network attack analysis learning
CN120200810A
Attack scene reconstruction method based on network threat clue causal mining
CN120263518A
Cited By
Network link reliability monitoring method and device, medium and program product
CN121173711A
Intrusion detection system applied to network security field
CN121441596A
Hierarchical calculation unloading and energy efficiency self-adaption computer system based on edge intelligence
CN122064398A
A hierarchical computing offloading and energy efficiency adaptive computer system based on edge intelligence
CN122064398B