Network threat detection method and device, equipment and storage medium

Through multi-dimensional data fusion and intelligent modeling, problems such as incomplete single-dimensional data coverage, delayed threat assessment, and high false alarm rate in the network security monitoring system have been solved, achieving early identification and efficient response to network threats.

CN120675764APending Publication Date: 2025-09-19INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Patent Information

Application Number
CN202510822410.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

The existing network security monitoring system relies on single network traffic analysis and lacks terminal behavior data integration, resulting in insufficient internal threat identification rate. The threat assessment model does not consider time series characteristics and cannot effectively detect latent attacks. There are also problems such as data silos, single analysis dimension, and delayed response, making it difficult to deal with new complex attacks.

Method used

By capturing multi-dimensional data from the network layer, terminal layer and intelligence layer, performing preset data processing and entity extraction, using the long-short-term memory network model to capture the attack timing characteristics, and constructing a target knowledge graph, combined with the CVSS vulnerability score, spatiotemporal correction factor and attack chain integrity coefficient, network threat events and their risk levels are determined, and a visual decision support system is constructed.

Benefits of technology

It has achieved three-dimensional data fusion at the network layer, terminal layer, and intelligence layer, enhanced the early warning capability for covert attacks, shortened emergency response time, and improved the accuracy of threat assessment and response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675764A_ABST
    Figure CN120675764A_ABST
Patent Text Reader

Abstract

The invention discloses a network threat detection method, device and equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: executing a preset data collection operation to capture initial multi-dimensional data, and carrying out the preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; executing a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, storing the target entity in a preset database, and inputting the target entity into a preset long-short-term memory network model to obtain attack time sequence characteristics; inputting the attack time sequence features into a target graph neural network model to construct a target knowledge graph, and determining a cross-device abnormal behavior chain based on the target knowledge graph; and determining an attack chain integrity coefficient according to the cross-device abnormal behavior chain, and determining a network threat event and a target risk level by using the CVSS vulnerability score, the space-time correction factor and the attack chain integrity coefficient to complete network threat detection. The problems of incomplete single-dimensional data coverage, high false alarm rate and the like can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network threat detection method, device, equipment and storage medium. Background Art

[0002] Currently, network security monitoring systems rely solely on network traffic analysis and lack the integration of endpoint behavior data. This results in insufficient internal threat identification rates, and threat assessment models fail to consider time series characteristics, making them ineffective in detecting latent attacks. Furthermore, traditional solutions suffer from data silos, a single analysis dimension, and delayed responses, making them inadequate for addressing new, complex attacks. Therefore, it is necessary to break down the barriers of multi-source data and achieve three-dimensional data integration across the network, endpoint, and intelligence layers; establish a dynamic risk assessment mechanism to enhance early warning capabilities for covert attacks; and build a visual decision support system to shorten emergency response times.

[0003] To sum up, how to solve the problems of incomplete coverage of single-dimensional data, delayed threat assessment, and high false alarm rate is an urgent issue that needs to be solved. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a network threat detection method, device, equipment and storage medium that can solve the problems of incomplete single-dimensional data coverage, delayed threat assessment, high false alarm rate, etc. The specific solution is as follows:

[0005] In a first aspect, the present application provides a network threat detection method, comprising:

[0006] Executing a preset data collection operation to capture initial multi-dimensional data, and performing a preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; wherein the initial multi-dimensional data is data captured from the network layer dimension, the terminal layer dimension, and the intelligence layer dimension;

[0007] Performing a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, storing the target entity in a preset database, and inputting the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack time series features;

[0008] Input the attack timing features into a target graph neural network model containing a preset time decay factor to construct a corresponding target knowledge graph, and determine the corresponding cross-device abnormal behavior chain based on the target knowledge graph;

[0009] The corresponding attack chain integrity coefficient is determined based on the cross-device abnormal behavior chain, and the corresponding network threat event is determined using the obtained CVSS vulnerability score, time and space correction factor and the attack chain integrity coefficient, and the target risk level corresponding to the network threat event is determined to complete network threat detection.

[0010] Optionally, executing a preset data acquisition operation to capture initial multi-dimensional data includes:

[0011] Using a preset network probe to capture first dimension data of the network layer dimension;

[0012] Using a preset terminal agent program to capture the second dimension data of the terminal layer dimension;

[0013] Using the preset threat intelligence subscription to capture the third dimension data of the intelligence layer dimension;

[0014] A preset data fusion operation is performed on the first dimensional data, the second dimensional data, and the first dimensional data to determine initial multi-dimensional data.

[0015] Optionally, inputting the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack timing features includes:

[0016] Inputting the target entities in the preset database into a preset long short-term memory network model to capture the target relationships between the target entities;

[0017] The corresponding attack timing characteristics are determined according to the target relationship between the target entities.

[0018] Optionally, inputting the attack timing features into a target graph neural network model including a preset time decay factor to construct a corresponding target knowledge graph includes:

[0019] Determine a corresponding preset time attenuation factor based on a preset scenario;

[0020] Deeply integrate the preset time decay factor into the preset core link of the initial graph neural network model to obtain the target graph neural network model;

[0021] The attack timing features are input into the target graph neural network model to construct a corresponding target knowledge graph.

[0022] Optionally, the determining a corresponding network threat event using the obtained CVSS vulnerability score, spatiotemporal correction factor, and the attack chain integrity coefficient, and determining a target risk level corresponding to the network threat event, includes:

[0023] Obtain the corresponding CVSS vulnerability score, intelligence confidence level, and enterprise asset weight based on the preset business scenario;

[0024] Determine a corresponding basic threat value using the obtained CVSS vulnerability score and the intelligence confidence level, and determine a corresponding spatiotemporal correction factor using the enterprise asset weight;

[0025] Determine a corresponding network threat event and a target risk value of the network threat event based on the basic threat value, the spatiotemporal correction factor, and the attack chain integrity coefficient;

[0026] Determine a preset risk value range corresponding to the target risk value;

[0027] The target risk level corresponding to the network threat event is obtained according to the preset risk value range of the target risk value.

[0028] Optionally, the determining a corresponding basic threat value using the obtained CVSS vulnerability score and the intelligence confidence, and determining a corresponding spatiotemporal correction factor using the enterprise asset weight, includes:

[0029] Performing a weighted operation on the CVSS vulnerability score based on a preset first weight coefficient to obtain a first weighted result, and performing a weighted operation on the intelligence confidence based on a preset second weight coefficient to obtain a second weighted result, and superimposing the first weighted result and the second weighted result to generate a basic threat value; wherein the first weight coefficient and the second weight coefficient are non-negative values, and the sum of the first weight coefficient and the second weight coefficient does not exceed a preset value;

[0030] Determine the time function parameters of the logistic growth function, and generate corresponding spatiotemporal correction factors based on the time function parameters and the enterprise asset weight; wherein the time function parameters include the steepness of the curve of the logistic growth function, the cumulative time since the first detection of the network threat, and the preset critical time threshold.

[0031] Optionally, after determining the target risk level corresponding to the network threat event, the method further includes:

[0032] Using a three-dimensional visualization engine to perform a preset attack path deduction operation on the network threat event to obtain a target attack path corresponding to the network threat event;

[0033] Generate a corresponding visualization chart based on the target attack path corresponding to the network threat event to complete network threat detection.

[0034] In a second aspect, the present application provides a network threat detection device, comprising:

[0035] a data acquisition module, configured to execute a preset data acquisition operation to capture initial multi-dimensional data, and perform a preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; wherein the initial multi-dimensional data is data captured from the network layer dimension, the terminal layer dimension, and the intelligence layer dimension;

[0036] a feature acquisition module, configured to perform a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, store the target entity in a preset database, and input the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack time series features;

[0037] a cross-device abnormal behavior chain determination module, configured to input the attack timing features into a target graph neural network model including a preset time decay factor to construct a corresponding target knowledge graph, and determine the corresponding cross-device abnormal behavior chain based on the target knowledge graph;

[0038] The network threat detection completion module is used to determine the corresponding attack chain integrity coefficient based on the cross-device abnormal behavior chain, use the obtained CVSS vulnerability score, spatiotemporal correction factor and the attack chain integrity coefficient to determine the corresponding network threat event, and determine the target risk level corresponding to the network threat event, and perform the corresponding preset network threat processing operation based on the target risk level of the network threat event to complete network threat detection.

[0039] In a third aspect, the present application provides an electronic device, comprising:

[0040] Memory, used to store computer programs;

[0041] The processor is configured to execute the computer program to implement the aforementioned network threat detection method.

[0042] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the network threat detection method as described above is implemented.

[0043] In summary, the present application first executes a preset data acquisition operation to capture initial multi-dimensional data, and performs a preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; wherein, the initial multi-dimensional data is data captured from the network layer dimension, the terminal layer dimension and the intelligence layer dimension; a preset entity extraction operation is performed on the processed multi-dimensional data to obtain a target entity, the target entity is stored in a preset database, and the target entity in the preset database is input into a preset long-short-term memory network model to obtain corresponding attack timing features; the attack timing features are input into a target graph neural network model containing a preset time attenuation factor to construct a corresponding target knowledge graph, and a corresponding cross-device abnormal behavior chain is determined based on the target knowledge graph; a corresponding attack chain integrity coefficient is determined based on the cross-device abnormal behavior chain, and the corresponding network threat event is determined using the obtained CVSS vulnerability score, spatiotemporal correction factor and the attack chain integrity coefficient, and the target risk level corresponding to the network threat event is determined to complete network threat detection. As can be seen from the above, this application first captures the initial multi-dimensional data from the network layer, terminal layer and intelligence layer dimensions and performs preset data processing to obtain processed multi-dimensional data, then performs preset entity extraction on it to obtain the target entity and stores it in a preset database, inputs the target entity in the database into the preset long-short term memory network model to obtain the attack timing characteristics, and then inputs the attack timing characteristics into the target graph neural network model containing the preset time attenuation factor to construct the target knowledge graph, determines the cross-device abnormal behavior chain based on the graph, determines the attack chain integrity coefficient based on the behavior chain, and finally uses the obtained CVSS vulnerability score, spatiotemporal correction factor and attack chain integrity coefficient to determine the network threat event and its corresponding target risk level, thereby completing network threat detection. In this way, the barriers of multi-source data are broken, and three-dimensional data fusion of the network layer, terminal layer and intelligence layer is realized; a dynamic risk assessment mechanism is established to enhance the early warning capability of covert attacks; and a visual decision support system is constructed to shorten the emergency response time. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0045] Figure 1 A flowchart of a network threat detection method disclosed in this application;

[0046] Figure 2 A flowchart for generating a specific knowledge graph disclosed in this application;

[0047] Figure 3 This is a logic block diagram of a specific threat scoring algorithm disclosed in this application;

[0048] Figure 4 This is a system architecture diagram of a network threat detection method disclosed in this application;

[0049] Figure 5 This is a schematic diagram of the structure of a network threat detection device disclosed in this application;

[0050] Figure 6 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0051] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0052] At present, the network security monitoring system relies on single network traffic analysis and lacks the integration of terminal behavior data, resulting in insufficient internal threat recognition rate. The threat assessment model does not take into account time series characteristics and cannot effectively detect latent attacks. In addition, traditional solutions have problems such as data silos, single analysis dimension, and delayed response, making it difficult to deal with new types of complex attacks. Therefore, it is necessary to break down the barriers of multi-source data and realize three-dimensional data fusion of the network layer, terminal layer, and intelligence layer; establish a dynamic risk assessment mechanism to enhance the early warning capability of covert attacks; and build a visual decision support system to shorten the emergency response time. In order to solve the above technical problems, the present application discloses a network threat detection method, device, equipment and storage medium, which can solve the problems of incomplete single-dimensional data coverage, delayed threat assessment, and high false alarm rate.

[0053] See also Figure 1 As shown, an embodiment of the present invention discloses a network threat detection method, including:

[0054] Step S11: Execute a preset data acquisition operation to capture initial multi-dimensional data, and perform a preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; wherein, the initial multi-dimensional data is data captured from the network layer dimension, the terminal layer dimension, and the intelligence layer dimension.

[0055] In this embodiment, it is first necessary to obtain network data from multiple dimensions. The preset network probe can be used to capture the first dimension data of the network layer dimension; the preset terminal agent program can be used to capture the second dimension data of the terminal layer dimension; the preset threat intelligence subscription can be used to capture the third dimension data of the intelligence layer dimension; the first dimension data, the first dimension data and the first dimension data are subjected to a preset data fusion operation to determine the initial multi-dimensional data. Specifically, a transparent bridging mode is used to access the core switch, and a preset network probe is deployed through DPDK acceleration technology. VXLAN / GRE tunnel decapsulation is supported in the preset network probe to extract five-tuples and payload features, i.e., first dimension data. At the same time, a terminal agent program is used to capture file creation / modification events based on the inotify mechanism, calculate the process behavior entropy value, and detect abnormal handle access to key processes, such as LSASS or sshd, in real time through eBPF to obtain the second dimension data of the terminal layer dimension. In addition, threat intelligence subscriptions are also available, which can automatically synchronize MITRE ATT&CK TTPs, AlienVault OTX, and commercial threat intelligence data in STIX / TAXII format, and establish an IP reputation database and vulnerability signature database, i.e., third-dimensional data. Then, the first-dimensional data, the second-dimensional data, and the third-dimensional data are fused to obtain the initial multi-dimensional data.

[0056] Furthermore, the initial multi-dimensional data is preprocessed. First, a stream processing engine is used to clean and normalize the initial multi-dimensional data. Then, a data cleaning filter is used to remove irrelevant data from the initial multi-dimensional data, such as normal network scans, false alarm logs, and malicious interference, such as attacker-generated noise traffic. This reduces the false positive rate in subsequent analysis. Furthermore, the log format, timestamp, and protocol fields are unified to address differences between device manufacturers and support cross-device correlation analysis. After processing the initial multi-dimensional data, processed multi-dimensional data is obtained.

[0057] Step S12: performing a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, storing the target entity in a preset database, and inputting the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack timing characteristics.

[0058] In this embodiment, after obtaining the processed multi-dimensional data, as shown in FIG. Figure 2As shown, a preset entity extraction operation is performed on the processed multi-dimensional data to obtain target entities and store them in a preset database. Next, the target entities in the preset database are input into a preset long-short-term memory network model to capture the target relationships between the target entities. Corresponding attack timing characteristics are determined based on the target relationships between the target entities. Specifically, the target entities in the preset database are input into a preset LSTM (Long Short-Term Memory) model. By capturing long-term dependencies in time series, the temporal patterns of network attacks, such as latent behavior and periodic attacks, can be effectively identified to determine the corresponding attack timing characteristics. The parameter range of the preset LSTM model can be adjusted accordingly, for example, the number of hidden layer units can be adjusted to 64-256, preferably 128, and the sliding window duration can be adjusted to 30-120 minutes, with 60 minutes being the optimal implementation.

[0059] Step S13: Input the attack timing features into a target graph neural network model containing a preset time attenuation factor to construct a corresponding target knowledge graph, and determine the corresponding cross-device abnormal behavior chain based on the target knowledge graph.

[0060] In this embodiment, it is necessary to determine a corresponding preset time decay factor based on a preset scenario; deeply integrate the preset time decay factor into the preset core link of the initial graph neural network model to obtain a target graph neural network model; and input the attack timing characteristics into the target graph neural network model to construct a corresponding target knowledge graph. Specifically, based on the preset scenario as shown in Table 1, the corresponding time decay factor β is determined, and the target graph neural network model is obtained by deeply integrating the time decay factor β into the core links of the GNN (Graph Neural Network) model, such as neighbor sampling, aggregation function, and node update. The target graph neural network model can more accurately model the target knowledge graph of dynamic network threats and determine the cross-device abnormal behavior chain based on the target knowledge graph:

[0061] ;

[0062] in, is the feature vector of node v in the kth layer, representing the dynamic state of the node in the knowledge graph; It is a nonlinear activation function (such as ReLU, Sigmoid) used to enhance the expressiveness of the model; is the trainable weight matrix of the Kth layer, used to linearly transform the neighbor aggregation results; Neighbor information aggregation function (such as mean, sum, or maximum) is used to integrate the features of adjacent nodes; is the time decay factor, which controls the influence weight of neighbor node u on the current node v; is the hidden state (feature vector) of node u in the k−1 layer; is the neighbor set of node v, which consists of network devices, user entities and protocol relationships.

[0063] Table 1

[0064]

[0065] Step S14: Determine the corresponding attack chain integrity coefficient based on the cross-device abnormal behavior chain, use the obtained CVSS vulnerability score, spatiotemporal correction factor, and the attack chain integrity coefficient to determine the corresponding network threat event, and determine the target risk level corresponding to the network threat event to complete network threat detection.

[0066] In this embodiment, after determining the cross-device abnormal behavior chain, Figure 3 As shown in Table 2, the attack chain integrity coefficient is determined based on the cross-device abnormal behavior chain. Then, based on the preset business scenario, the corresponding CVSS vulnerability score, intelligence confidence, and enterprise asset weight are obtained. The obtained CVSS vulnerability score and intelligence confidence are used to determine the corresponding base threat value, and the corresponding spatiotemporal correction factor is used to determine the corresponding enterprise asset weight. Based on the base threat value, the spatiotemporal correction factor, and the attack chain integrity coefficient, the corresponding network threat event and the target risk value of the network threat event are determined. A preset risk value range corresponding to the target risk value is determined. Based on the preset risk value range of the target risk value, the target risk level corresponding to the network threat event is obtained. Specifically, based on the preset business scenario, the CVSS (Common Vulnerability Scoring System) vulnerability score, intelligence confidence, and enterprise asset weight are obtained. The CVSS vulnerability score is mapped to a threat value range and weighted and adjusted with intelligence confidence to obtain the base threat value. The spatiotemporal correction factor is then dynamically adjusted to consider the changes in asset vulnerability in the spatiotemporal environment. The target risk value of the network threat event is determined using a preset calculation model. The calculation model is shown below:

[0067] ;

[0068] in, The basic threat value is based on the inherent risk of the vulnerability and the credibility of the intelligence; is the spatiotemporal correction factor, which dynamically amplifies or suppresses the spatiotemporal sensitivity of the threat value; min() is the minimum value of the formula; the attack chain integrity coefficient quantifies the maturity of the attacker in completing the intrusion steps.

[0069] Finally, the target risk value is compared with the preset risk value range, and the mapping is performed to obtain the low, medium-low, medium, medium-high, and high risk levels as shown in Table 3, providing a basis for subsequent protection.

[0070] Table 2

[0071]

[0072] Table 3

[0073]

[0074] Furthermore, to obtain the base threat value and spatiotemporal correction factor, the CVSS vulnerability score is weighted based on a preset first weighting coefficient to obtain a first weighted result, and the intelligence confidence level is weighted based on a preset second weighting coefficient to obtain a second weighted result. The first and second weighting coefficients are superimposed to generate the base threat value. The first and second weighting coefficients are non-negative, and their sum does not exceed a preset value. A time function parameter of the logistic growth function is determined, and a corresponding spatiotemporal correction factor is generated based on the time function parameter and the enterprise asset weight. The time function parameter includes the steepness of the logistic growth function curve, the accumulated time since the initial detection of the network threat, and a preset critical time threshold. Specifically, to obtain the base threat value, the first and second weighting coefficients are set based on the business scenario characteristics and security protection strategy. Both are non-negative values, and their sum does not exceed 1. The CVSS vulnerability score is weighted by the first weighting coefficient to reflect the contribution of the vulnerability's inherent harm to the threat assessment. The intelligence confidence level is weighted by the second weighting coefficient to reflect the impact of intelligence reliability on threat assessment. Add the first weighted result and the second weighted result to get the basic threat value:

[0075] ;

[0076] in, The basic threat value is a combination of the inherent risk of the vulnerability and the credibility of the intelligence; CVSS is the inherent severity score of the vulnerability (0-10 points); the intelligence confidence is the credibility of the threat intelligence (0-1, such as 0.9 means 90% reliable); and The weight is dynamically adjusted according to the business scenario, usually + ≤1.

[0077] When determining the spatiotemporal correction factor, the logistic growth function is introduced, and the setting of its time function parameters is crucial. The steepness of the curve reflects the growth rate of network threats over time and can be empirically assigned based on historical attack data or industry security trends. The cumulative time since the initial detection of the network threat is used to measure the duration of the threat. The preset critical time threshold represents the time point when the threat develops to a specific level of danger. Combined with the enterprise's asset weights, the time function parameters are substituted into the logistic growth function model to calculate the coefficient of change in the asset's vulnerability to threats at different time points. This coefficient is the spatiotemporal correction factor:

[0078] ;

[0079] in, is a spatiotemporal correction factor that dynamically amplifies or suppresses the spatiotemporal sensitivity of the threat value. k is the steepness of the curve, which defaults to 0.5 and is increased to 1.0 when the threat spreads rapidly. t is the current time (starting from the first detection of the threat). The critical time for the threat to spread is set to 24 hours, for example; the enterprise asset weight is the importance of the affected assets.

[0080] For example, if 12 hours have passed since the threat was first detected (t=12), let k=0.5, =24, enterprise asset weight =3:

[0081] ;

[0082] We can know that t=12, k=0.5, =24, and the time-space correction factor when the enterprise asset weight = 3 is 0.0075.

[0083] Furthermore, a three-dimensional visualization engine is used to perform a preset attack path deduction operation on the network threat event to obtain the target attack path corresponding to the network threat event; based on the target attack path corresponding to the network threat event, a corresponding visualization chart is generated to complete network threat detection. Specifically, after risk assessment, data such as the cross-device abnormal behavior chain and target risk value are imported into the three-dimensional visualization engine. Combined with the CVSS vulnerability score and intelligence confidence, the attacker's technical means are simulated based on the deduction algorithm to construct multiple potential attack paths. The most likely target attack path is screened out through the algorithm, and then the visualization engine is used to integrate key nodes, attack means and other information to generate visualizations such as timelines, asset relationship diagrams, and attack traffic heat maps to complete network threat detection.

[0084] As can be seen from the above, the embodiment of the present application first captures the initial multi-dimensional data from the network layer, terminal layer and intelligence layer dimensions and performs preset data processing to obtain processed multi-dimensional data, then performs preset entity extraction on it to obtain the target entity and stores it in a preset database, inputs the target entity in the database into the preset long-short term memory network model to obtain the attack timing characteristics, and then inputs the attack timing characteristics into the target graph neural network model containing the preset time attenuation factor to construct the target knowledge graph, determines the cross-device abnormal behavior chain based on the graph, determines the attack chain integrity coefficient based on the behavior chain, and finally uses the obtained CVSS vulnerability score, spatiotemporal correction factor and attack chain integrity coefficient to determine the network threat event and its corresponding target risk level, thereby completing network threat detection. In this way, the barriers of multi-source data are broken, and three-dimensional data fusion of the network layer, terminal layer and intelligence layer is realized; a dynamic risk assessment mechanism is established to enhance the early warning capability of covert attacks; and a visual decision support system is constructed to shorten the emergency response time.

[0085] Based on the previous embodiment, this application discloses a network threat detection method that is applicable to enterprise-level network security monitoring, critical infrastructure protection, and cloud environment security operation and maintenance scenarios. It can solve problems such as incomplete single-dimensional data coverage, delayed threat assessment, and high false alarm rate. Figure 4 The network threat detection method shown is described in detail.

[0086] First, the present application captures data from the network layer dimension, the terminal layer dimension and the intelligence layer dimension, and fuses the data captured from each dimension to obtain initial multi-dimensional data, then performs data preprocessing on the initial multi-dimensional data, and uses a stream processing engine and a data cleaning filter to obtain processed multi-dimensional data after processing the initial multi-dimensional data. After obtaining the processed multi-dimensional data, a preset entity extraction operation is performed on the processed multi-dimensional data to obtain the target entity and store it in a preset database. The target entity in the preset database is input into a preset LSTM model, and by capturing the long-term dependencies in the time series, the timing pattern of the network attack can be effectively identified to determine the corresponding attack timing characteristics. Then, based on the preset scenario, the corresponding time decay factor β is determined, and the target graph neural network model is obtained by deeply integrating the time decay factor β into the core links of the GNN model such as neighbor sampling, aggregation function, and node update. The target graph neural network model can more accurately model the target knowledge graph of dynamic network threats, and determine the cross-device abnormal behavior chain based on the target knowledge graph, and determine the corresponding attack chain integrity coefficient based on the cross-device abnormal behavior chain. Subsequently, the CVSS vulnerability score, intelligence confidence level, and enterprise asset weight are obtained based on the preset business scenario. The CVSS vulnerability score is mapped to the threat value range, and the intelligence confidence level is weighted and adjusted to obtain the basic threat value. The vulnerability changes of assets in the spatiotemporal environment are then taken into consideration, and the asset weight is dynamically adjusted to form a spatiotemporal correction factor. The preset calculation model is then used to determine the target risk value and risk level of network threat events.

[0087] See also Figure 5 As shown, an embodiment of the present invention discloses a network threat detection device, comprising:

[0088] The data acquisition module 11 is configured to execute a preset data acquisition operation to capture initial multi-dimensional data, and perform a preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; wherein the initial multi-dimensional data is data captured from the network layer dimension, the terminal layer dimension, and the intelligence layer dimension;

[0089] A feature acquisition module 12 is configured to perform a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, store the target entity in a preset database, and input the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack time series features;

[0090] A cross-device abnormal behavior chain determination module 13 is configured to input the attack timing characteristics into a target graph neural network model including a preset time decay factor to construct a corresponding target knowledge graph, and determine a corresponding cross-device abnormal behavior chain based on the target knowledge graph;

[0091] The network threat detection completion module 14 is used to determine the corresponding attack chain integrity coefficient based on the cross-device abnormal behavior chain, use the obtained CVSS vulnerability score, spatiotemporal correction factor and the attack chain integrity coefficient to determine the corresponding network threat event, and determine the target risk level corresponding to the network threat event, and perform the corresponding preset network threat processing operation based on the target risk level of the network threat event to complete network threat detection.

[0092] As can be seen from the above, this application first captures the initial multi-dimensional data from the network layer, terminal layer and intelligence layer dimensions and performs preset data processing to obtain processed multi-dimensional data, then performs preset entity extraction on it to obtain the target entity and stores it in a preset database, inputs the target entity in the database into the preset long-short term memory network model to obtain the attack timing characteristics, and then inputs the attack timing characteristics into the target graph neural network model containing the preset time attenuation factor to construct the target knowledge graph, determines the cross-device abnormal behavior chain based on the graph, determines the attack chain integrity coefficient based on the behavior chain, and finally uses the obtained CVSS vulnerability score, spatiotemporal correction factor and attack chain integrity coefficient to determine the network threat event and its corresponding target risk level, thereby completing network threat detection. In this way, the barriers of multi-source data are broken, and three-dimensional data fusion of the network layer, terminal layer and intelligence layer is realized; a dynamic risk assessment mechanism is established to enhance the early warning capability of covert attacks; and a visual decision support system is constructed to shorten the emergency response time.

[0093] In some specific implementations, the data acquisition module 11 may specifically include:

[0094] A first dimension data capturing unit, configured to capture first dimension data of the network layer dimension using a preset network probe;

[0095] A second dimension data capturing unit, configured to capture the second dimension data of the terminal layer dimension using a preset terminal agent program;

[0096] A third dimension data capture unit, configured to capture the third dimension data of the intelligence layer dimension by using a preset threat intelligence subscription;

[0097] The initial multi-dimensional data determining unit is configured to perform a preset data fusion operation on the first dimensional data, the second dimensional data, and the first dimensional data to determine initial multi-dimensional data.

[0098] In some specific implementations, the feature acquisition module 12 may specifically include:

[0099] a target relationship capturing unit, configured to input the target entities in the preset database into a preset long short-term memory network model to capture the target relationship between the target entities;

[0100] The attack time series feature determination unit is used to determine the corresponding attack time series feature according to the target relationship between the target entities.

[0101] In some specific implementations, the cross-device abnormal behavior chain determination module 13 may specifically include:

[0102] A preset time attenuation factor determining unit, configured to determine a corresponding preset time attenuation factor based on a preset scenario;

[0103] A target graph neural network model acquisition unit, configured to deeply integrate the preset time attenuation factor into a preset core link of the initial graph neural network model to obtain a target graph neural network model;

[0104] The target knowledge graph construction unit is used to input the attack timing features into the target graph neural network model to construct a corresponding target knowledge graph.

[0105] In some specific implementations, the network threat detection completion module 14 may specifically include:

[0106] Scoring, confidence, and weight acquisition unit, used to obtain corresponding CVSS vulnerability scores, intelligence confidence, and enterprise asset weights based on preset business scenarios;

[0107] a basic threat value and spatiotemporal correction factor determination unit, configured to determine a corresponding basic threat value using the obtained CVSS vulnerability score and the intelligence confidence level, and to determine a corresponding spatiotemporal correction factor using the enterprise asset weight;

[0108] a target risk value determining unit, configured to determine a corresponding network threat event and a target risk value of the network threat event based on the basic threat value, the spatiotemporal correction factor, and the attack chain integrity coefficient;

[0109] a preset risk value range determining unit, configured to determine a preset risk value range corresponding to the target risk value;

[0110] The target risk level acquisition unit is configured to obtain the target risk level corresponding to the network threat event according to a preset risk value range of the target risk value.

[0111] In some specific implementations, the basic threat value and spatiotemporal correction factor determination unit may specifically include:

[0112] a basic threat value generating subunit, configured to perform a weighted operation on the CVSS vulnerability score based on a preset first weight coefficient to obtain a first weighted result, perform a weighted operation on the intelligence confidence level based on a preset second weight coefficient to obtain a second weighted result, and superimpose the first weighted result and the second weighted result to generate a basic threat value; wherein the first weight coefficient and the second weight coefficient are non-negative values, and the sum of the first weight coefficient and the second weight coefficient does not exceed a preset value;

[0113] The spatiotemporal correction factor generation subunit is used to determine the time function parameters of the logistic growth function, and generate corresponding spatiotemporal correction factors based on the time function parameters and the enterprise asset weight; wherein, the time function parameters may specifically include the steepness of the curve of the logistic growth function, the cumulative time since the first detection of the network threat, and the preset critical time threshold.

[0114] In some specific implementations, the network threat detection device further includes:

[0115] A target attack path acquisition module is used to use a three-dimensional visualization engine to perform a preset attack path deduction operation on the network threat event to obtain a target attack path corresponding to the network threat event;

[0116] The network threat detection completion module is used to generate a corresponding visual chart based on the target attack path corresponding to the network threat event to complete the network threat detection.

[0117] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram should not be considered as any limitation to the scope of application of the present application.

[0118] Figure 6 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the network threat detection method disclosed in any of the aforementioned embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0119] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0120] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0121] The operating system 221 is used to manage and control the hardware devices on the electronic device 20 and the computer program 222, and can be Windows Server, NetWare, Unix, Linux, etc. In addition to including a computer program capable of implementing the network threat detection method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program capable of performing other specific tasks.

[0122] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when executed by a processor, the computer program implements the aforementioned network threat detection method. The specific steps of this method can be referred to the corresponding content disclosed in the aforementioned embodiments and will not be repeated here.

[0123] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.

[0124] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0125] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0126] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0127] The above is a detailed introduction to the technical solution provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the ideas of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A network threat detection method, characterized in that: include: Executing a preset data collection operation to capture initial multi-dimensional data, and performing a preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; wherein the initial multi-dimensional data is data captured from the network layer dimension, the terminal layer dimension, and the intelligence layer dimension; Performing a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, storing the target entity in a preset database, and inputting the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack time series features; Input the attack timing features into a target graph neural network model containing a preset time decay factor to construct a corresponding target knowledge graph, and determine the corresponding cross-device abnormal behavior chain based on the target knowledge graph; The corresponding attack chain integrity coefficient is determined based on the cross-device abnormal behavior chain, and the corresponding network threat event is determined using the obtained CVSS vulnerability score, time and space correction factor and the attack chain integrity coefficient, and the target risk level corresponding to the network threat event is determined to complete network threat detection.

2. The network threat detection method according to claim 1, characterized in that: The performing of the preset data collection operation to capture the initial multi-dimensional data includes: Using a preset network probe to capture first dimension data of the network layer dimension; Using a preset terminal agent program to capture the second dimension data of the terminal layer dimension; Using the preset threat intelligence subscription to capture the third dimension data of the intelligence layer dimension; A preset data fusion operation is performed on the first dimensional data, the second dimensional data, and the first dimensional data to determine initial multi-dimensional data.

3. The network threat detection method according to claim 1, wherein: The step of inputting the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack timing features includes: Inputting the target entities in the preset database into a preset long short-term memory network model to capture the target relationships between the target entities; The corresponding attack timing characteristics are determined according to the target relationship between the target entities.

4. The network threat detection method according to claim 1, wherein: Inputting the attack timing features into a target graph neural network model including a preset time decay factor to construct a corresponding target knowledge graph includes: Determine a corresponding preset time attenuation factor based on a preset scenario; Deeply integrate the preset time decay factor into the preset core link of the initial graph neural network model to obtain the target graph neural network model; The attack timing features are input into the target graph neural network model to construct a corresponding target knowledge graph.

5. The network threat detection method according to claim 1, wherein: The determining of a corresponding network threat event using the obtained CVSS vulnerability score, the spatiotemporal correction factor, and the attack chain integrity coefficient, and determining a target risk level corresponding to the network threat event, includes: Obtain the corresponding CVSS vulnerability score, intelligence confidence level, and enterprise asset weight based on the preset business scenario; Determine a corresponding basic threat value using the obtained CVSS vulnerability score and the intelligence confidence level, and determine a corresponding spatiotemporal correction factor using the enterprise asset weight; Determine a corresponding network threat event and a target risk value of the network threat event based on the basic threat value, the spatiotemporal correction factor, and the attack chain integrity coefficient; Determine a preset risk value range corresponding to the target risk value; The target risk level corresponding to the network threat event is obtained according to the preset risk value range of the target risk value.

6. The network threat detection method according to claim 5, characterized in that: The method of determining a corresponding basic threat value using the obtained CVSS vulnerability score and the intelligence confidence level, and determining a corresponding spatiotemporal correction factor using the enterprise asset weight, includes: Performing a weighted operation on the CVSS vulnerability score based on a preset first weight coefficient to obtain a first weighted result, and performing a weighted operation on the intelligence confidence based on a preset second weight coefficient to obtain a second weighted result, and superimposing the first weighted result and the second weighted result to generate a basic threat value; wherein the first weight coefficient and the second weight coefficient are non-negative values, and the sum of the first weight coefficient and the second weight coefficient does not exceed a preset value; Determine the time function parameters of the logistic growth function, and generate corresponding spatiotemporal correction factors based on the time function parameters and the enterprise asset weight; wherein the time function parameters include the steepness of the curve of the logistic growth function, the cumulative time since the first detection of the network threat, and the preset critical time threshold.

7. The network threat detection method according to claim 1, wherein: After determining the target risk level corresponding to the network threat event, the method further includes: Using a three-dimensional visualization engine to perform a preset attack path deduction operation on the network threat event to obtain a target attack path corresponding to the network threat event; Generate a corresponding visualization chart based on the target attack path corresponding to the network threat event to complete network threat detection.

8. A network threat detection device, characterized in that: include: a data acquisition module, configured to execute a preset data acquisition operation to capture initial multi-dimensional data, and perform a preset data processing operation on the initial multi-dimensional data to obtain processed multi-dimensional data; wherein the initial multi-dimensional data is data captured from the network layer dimension, the terminal layer dimension, and the intelligence layer dimension; a feature acquisition module, configured to perform a preset entity extraction operation on the processed multi-dimensional data to obtain a target entity, store the target entity in a preset database, and input the target entity in the preset database into a preset long short-term memory network model to obtain corresponding attack time series features; a cross-device abnormal behavior chain determination module, configured to input the attack timing features into a target graph neural network model including a preset time decay factor to construct a corresponding target knowledge graph, and determine the corresponding cross-device abnormal behavior chain based on the target knowledge graph; The network threat detection completion module is used to determine the corresponding attack chain integrity coefficient based on the cross-device abnormal behavior chain, use the obtained CVSS vulnerability score, spatiotemporal correction factor and the attack chain integrity coefficient to determine the corresponding network threat event, and determine the target risk level corresponding to the network threat event, and perform the corresponding preset network threat processing operation based on the target risk level of the network threat event to complete network threat detection.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the network threat detection method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the network threat detection method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Network risk sensing method and network risk defense method

    CN113709097A

  • Network attack threat analysis method and system based on knowledge graph

    CN118018256A

  • Network threat knowledge graph construction method based on SecBABC

    CN119106141A

  • Network attack link tracking and threat situation reasoning method based on knowledge graph

    CN119544327A

  • Network risk assessment method and system based on multi-modal data pre-training model

    CN119814354A

Cited By

  • Network security threat detection method and device, equipment and storage medium

    CN121125348A

  • Network security threat detection method, device, equipment and storage medium

    CN121125348B

  • Intelligent network operation and maintenance and security big data management platform based on multi-source data fusion

    CN121309070A

  • Video monitoring vulnerability detection method and device based on knowledge graph, and medium

    CN121309219A

  • A knowledge graph-based threat intelligence correlation method and system

    CN122490325A