Attack surface cross-domain incremental parallel updating method based on transformer model
By adopting a cross-domain incremental parallel update method based on the Transformer model, the problems of high resource consumption and data lag in network security scanning are solved, achieving efficient and accurate attack surface management and threat identification, and improving network security protection capabilities.
Patent Information
- Application Number
- CN202511137244.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-08-14
AI Technical Summary
Existing technologies consume excessive resources, have slow data updates, and poor scalability when performing network security scans in large-scale or cloud environments, making it impossible to effectively capture dynamic changes in the attack surface.
A cross-domain incremental parallel update method based on the Transformer model is adopted. By collecting incremental data from multiple domains, a unified cross-domain attack surface element identifier is established. The pre-trained Transformer model is used to capture the correlation between the incremental data of each domain, and weighted and depth constraints are applied to generate the overall attack surface increment. The attack surface knowledge base is dynamically updated and the model is fine-tuned based on security event feedback signals.
It enables efficient processing of multi-domain data, accurate identification and management of attack surfaces, timely detection of potential threats, and improved network security protection capabilities and management efficiency.
Smart Images

Figure CN120743920B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the field of network security, and in particular to an attack surface cross-domain incremental parallel updating method based on a Transformer model. BACKGROUND
[0002] The existing mainstream technical solution is usually based on a preset (such as daily or weekly) scanning and discovery cycle, and performs comprehensive asset discovery, port scanning, service identification, and vulnerability detection on a target network environment, and then compares and analyzes each item of the current full-scan result with the last full-scan result to identify changes, and updates the finally identified increment to the attack surface knowledge base. The core is periodic full collection and full comparison.
[0003] The main disadvantages of the existing technology are: 1) huge resource consumption: frequent full-scan consumes a large amount of computing, storage and network bandwidth resources, especially in large-scale or cloud environments, the cost is difficult to bear;
[0004] 2) data update lag: fixed-period scanning cannot capture attack surface changes within the scanning interval, resulting in an outdated security view, leaving a window period for attackers to exploit;
[0005] 3) poor scalability: in the face of transient environments and massive data, the scalability and timeliness of the full processing mode are limited. SUMMARY
[0006] The present disclosure provides an attack surface cross-domain incremental parallel updating method based on a Transformer model, which solves the technical problems of excessive system resource consumption, attack surface data update lag, and poor scalability of the existing technology based on fixed-period full identification and comparison in a dynamic and complex network environment.
[0007] According to a first aspect of the present disclosure, an attack surface cross-domain incremental parallel updating method based on a Transformer model is provided. The method comprises:
[0008] Collecting incremental data of multiple domains and preprocessing, establishing a unified attack surface element identifier across domains, and converting the incremental data of each domain into a vector representation to generate incremental feature vectors of each domain;
[0009] Processing the incremental feature vectors of each domain in parallel based on a pre-trained Transformer model, capturing the correlation between the increments of each domain, assigning weight coefficients to the increments of each domain, and outputting a correlation matrix;
[0010] Weighting the incremental feature vectors of each domain based on the weight coefficients, and performing deep correlation constraint and modulation on the weighted incremental feature vectors of each domain based on the correlation matrix to generate an overall attack surface increment.
[0011] The overall attack surface increment is written into the attack surface knowledge base for incremental updating, and the Transformer model is continuously fine-tuned based on the incremental updating result and a feedback signal of an actual security event.
[0012] According to the aspect and any possible implementation manner described above, further provided is an implementation manner, wherein the plurality of domains include a data domain, a network domain, a service domain, and a space-time domain.
[0013] According to the aspect and any possible implementation manner described above, further provided is an implementation manner, wherein the establishing of the cross-domain unified attack surface element identifier and the converting of the incremental data of each domain into a vector representation to generate the incremental feature vector of each domain include:
[0014] The potential attack surface elements are extracted from the preprocessed data of each domain, a unique identifier is generated for each attack surface element, and a cross-domain correlation is established by comparing the attack surface elements and the identifiers thereof in different domains.
[0015] According to the target and requirement of the attack surface analysis, a key attribute capable of effectively reflecting the characteristics of the attack surface elements is selected as the dimension of the feature vector, and the selected feature is quantified and coded to be converted into a numerical vector representation.
[0016] According to the aspect and any possible implementation manner described above, further provided is an implementation manner, wherein the processing of the incremental feature vectors of each domain in parallel by the pre-trained Transformer model, the capturing of the correlation between the incremental features of each domain, the assigning of the weight coefficients to the incremental features of each domain, and the outputting of the correlation matrix include:
[0017] The long-term dependency and the nonlinear interaction between the incremental feature vectors in the input sequence are automatically captured based on the self-attention mechanism, and the incremental feature vectors are assigned with weights.
[0018] The feature vectors processed by the self-attention mechanism are further nonlinearly transformed based on the feedforward neural network, and the transformed feature vectors are integrated to output the correlation matrix.
[0019] According to the aspect and any possible implementation manner described above, further provided is an implementation manner, wherein the incremental feature vectors of each domain are weighted based on the weight coefficients by using the following dynamic incremental fusion formula, and the incremental feature vectors of each domain after weighting are subjected to deep correlation constraint and modulation based on the correlation matrix to generate the overall attack surface increment.
[0020]
[0021] Wherein, AS(k) is the overall attack surface increment that needs to be updated in time step k; a, b, d, e are weight coefficients of data domain, network domain, service domain, and space-time domain increment, respectively; , , and are data domain increment, network domain increment, service domain increment, and space-time domain increment, respectively; g is a global scaling factor; is a fusion operation; is the correlation matrix output by the Transformer model after processing the current context information D.
[0022] According to the aspect and any possible implementation manner described above, an implementation manner is further provided, wherein the weight coefficients are dynamically adjusted according to real-time threat intelligence, service scenarios, or model confidence.
[0023] According to the aspect and any possible implementation manner described above, an implementation manner is further provided, wherein the pre-training process of the Transformer model comprises:
[0024] The historical multi-domain increment data and the attack surface state snapshot are input, and the corresponding overall attack surface actual increment is used as a supervision signal, and a self-supervised and supervised learning combined manner is used to train the Transformer model;
[0025] The cross-domain correlation patterns between the multi-domain increments are learned through the self-attention mechanism, the feature representation is optimized through the feedforward neural network, the model parameters are iteratively updated to minimize the error between the predicted increment and the actual increment, and the pre-trained Transformer model is obtained.
[0026] According to a second aspect of the present disclosure, an attack surface cross-domain increment parallel updating device based on a Transformer model is provided. The device comprises:
[0027] A feature vector generation module is configured to collect and preprocess the increment data of multiple domains, establish a cross-domain unified attack surface element identifier, convert the increment data of each domain into a vector representation, and generate the increment feature vectors of each domain;
[0028] A cross-domain correlation modeling module is configured to process the increment feature vectors of each domain input in parallel based on the pre-trained Transformer model, capture the correlation between the increments of each domain, assign weight coefficients to the increments of each domain, and output a correlation matrix;
[0029] An overall increment calculation module is configured to weight the increment feature vectors of each domain based on the weight coefficients, and perform deep correlation constraint and modulation on the weighted increment feature vectors of each domain based on the correlation matrix, to generate an overall attack surface increment.
[0030] a model optimization module, configured to write the overall attack surface increment into an attack surface knowledge base for incremental updating, and continuously fine-tune the Transformer model based on an incremental updating result and a feedback signal of an actual security event.
[0031] According to a third aspect of the present disclosure, an electronic device is provided. The electronic device comprises a memory and a processor, the memory having stored thereon a computer program, the processor implementing the method as described above when executing the program.
[0032] According to a fourth aspect of the present disclosure, a computer readable storage medium is provided, having stored thereon a computer program, the program being executed by a processor to implement the method according to the first aspect and / or the second aspect of the present disclosure.
[0033] In the present disclosure, first, by collecting and preprocessing the incremental data of multiple domains (such as data domain, network domain, business domain, and space-time domain), converting the incremental data of each domain into vector representation, and generating incremental feature vectors of each domain, efficient processing and unified representation of multi-domain data are achieved; second, by using a pre-trained Transformer model, automatically capturing long-term dependencies and nonlinear interactions between incremental feature vectors of each domain based on a self-attention mechanism, and outputting a correlation matrix, deep mining of cross-domain correlation is achieved; third, by dynamically adjusting the weight coefficient according to real-time threat intelligence, business scenarios, or model confidence through a dynamic incremental fusion formula, dynamic weighting and deep correlation constraint of different domain increments are achieved, and the adaptive ability of the model is improved; finally, by writing the overall attack surface increment into an attack surface knowledge base for incremental updating, and continuously fine-tuning the Transformer model based on an incremental updating result and a feedback signal of an actual security event, dynamic updating of the attack surface knowledge base and continuous optimization of the model are achieved. In this way, the attack surface can be more accurately identified and managed, potential security threats can be discovered in a timely manner, the accuracy and efficiency of attack surface management are improved, and the network security protection capability is enhanced.
[0034] It should be understood that the content described in the summary section is not intended to limit or define key or important features of the embodiments of the present disclosure, nor to limit the scope of the present disclosure. Other features of the present disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0035] The above and other features, advantages, and aspects of embodiments of the present disclosure will become more apparent by describing in detail some embodiments thereof with reference to the attached drawings. The drawings provided herein are for illustrative purposes only and are not intended to limit the scope of the present disclosure. In the drawings, the same or similar reference numerals denote the same or similar elements, and:
[0036] Figure 1 A flowchart of an attack surface cross-domain incremental parallel updating method based on a Transformer model provided by an embodiment of the present disclosure is shown.
[0037] Figure 2 A structural diagram of an attack surface cross-domain incremental parallel updating device based on a Transformer model provided by an embodiment of the present disclosure is shown.
[0038] Figure 3 A structural diagram of an exemplary electronic device capable of implementing an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be described below in a clear and complete manner with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. Based on the embodiments in the present disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present disclosure.
[0040] In addition, the term “and / or” herein is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B can represent the three cases of A alone, A and B together, and B alone. In addition, the character “ / ” herein generally represents an “or” relationship between the front and rear associated objects.
[0041] Before the technical solutions of the present disclosure are described in detail, the technical terms involved in the technical solutions are described first:
[0042] Data domain: refers to the collection of all information and resources related to data, including data storage, access, processing, transmission, and other aspects.
[0043] Network domain: refers to the collection of all information and resources related to the network, including network topology, network devices, network protocols, network traffic, and other aspects.
[0044] Business domain: refers to the collection of all information and resources related to the business processes, business logic, and business data of an enterprise or organization.
[0045] Space-time domain: refers to the collection of all information and resources related to time and space, including the geographical location of devices, the time distribution of user activities, and the spatio-temporal association of events.
[0046] Transformer model: A deep learning architecture based on self-attention mechanism, mainly used for processing sequential data (such as text, time series, etc.), which has achieved great success in natural language processing. It includes:
[0047] Self-attention mechanism: By calculating the dependency between the features of each position in the sequence and the features of other positions, dynamically assigning weights, and capturing long-range dependencies in the sequence.
[0048] Encoder-decoder structure: The Transformer model usually consists of an encoder and a decoder. The encoder encodes the input sequence into a context representation, and the decoder generates the output sequence based on the context representation.
[0049] Multi-head attention mechanism: The input sequence is divided into multiple "heads", each head independently calculates the attention weight, and then the outputs of multiple heads are spliced to further enhance the model's ability to model different subspaces.
[0050] Attack surface: It refers to the set of all potential weaknesses in a system or network that can be exploited by attackers. The larger the attack surface, the higher the risk of attack on the system or network.
[0051] In this disclosure, first, by collecting and preprocessing the incremental data of multiple domains (such as data domain, network domain, business domain, and spatio-temporal domain), converting the incremental data of each domain into vector representation, and generating incremental feature vectors of each domain, efficient processing and unified representation of multi-domain data are achieved; second, using the pre-trained Transformer model, automatically capturing the long-term dependencies and nonlinear interactions between the incremental feature vectors of each domain based on the self-attention mechanism, and outputting the correlation matrix, realizing the deep mining of cross-domain correlation; third, through the dynamic incremental fusion formula, dynamically adjusting the weight coefficient according to the real-time threat intelligence, business scenario or model confidence, realizing the dynamic weighting and deep correlation constraint of different domain increments, and improving the adaptive ability of the model; finally, by writing the overall attack surface increment into the attack surface knowledge base for incremental update, and continuously fine-tuning the Transformer model based on the incremental update result and the feedback signal of the actual security event, realizing the dynamic update of the attack surface knowledge base and the continuous optimization of the model. In this way, the attack surface can be more accurately identified and managed, potential security threats can be discovered in a timely manner, and the accuracy and efficiency of attack surface management are improved, and the network security protection capability is enhanced.
[0052] Figure 1 The flowchart of the attack surface cross-domain incremental parallel update method based on the Transformer model provided by the embodiment of the present disclosure is shown as follows: Figure 1As shown, the attack surface cross-domain incremental parallel updating method 100 based on the Transformer model can include the following steps:
[0053] S110, collecting incremental data of multiple domains and preprocessing, establishing a cross-domain unified attack surface element identifier, and converting incremental data of each domain into vector representation to generate incremental feature vectors of each domain.
[0054] In some embodiments, the multiple domains include data domains, network domains, business domains, and spatiotemporal domains.
[0055] In some embodiments, establishing a cross-domain unified attack surface element identifier and converting incremental data of each domain into vector representation to generate incremental feature vectors of each domain includes:
[0056] Extracting potential attack surface elements from preprocessed data of each domain, generating a unique identifier for each attack surface element, and establishing cross-domain associations by comparing attack surface elements and their identifiers in different domains;
[0057] According to the target and demand of attack surface analysis, select the key attributes that can effectively reflect the characteristics of attack surface elements as the dimensions of feature vectors, and quantize and encode the selected features to convert them into numerical vector representation.
[0058] For example, continuously or on-demand incremental data from multiple dimensions such as data domains, network domains, business domains, and spatiotemporal domains is collected; wherein incremental data refers to data that is newly added or changed compared to the last data collection period.
[0059] The collected data is preprocessed, standardized, normalized, etc. to ensure that data from different sources and different types can be effectively processed by subsequent models, and the preprocessed data of each domain is stored in a temporary database; wherein,
[0060] Data cleaning is used to remove noise data and invalid data. For example, filtering out abnormal data packets in network traffic (such as obviously incorrect IP addresses, excessively large data packets), and deleting duplicate records in business data.
[0061] Data standardization is used to convert data of different formats and units into a unified format. For example, converting time stamps to Coordinated Universal Time format, and converting numerical data of different units (such as Celsius and Fahrenheit) to a unified unit.
[0062] Data normalization is used to scale numerical data to the range [0, 1] for subsequent processing. For example, scaling network traffic size from byte units to the range [0, 1].
[0063] Exemplarily, the pre-processed data of each domain is called from the temporary database, and potential attack surface elements in each domain are extracted through preset element identification rules (such as keyword matching, pattern recognition algorithm, etc.). For example, the possible attack surface elements in the network domain include IP address, port number, etc.; the data domain may include sensitive data fields, data access permissions, etc.
[0064] A unique identifier is generated for each extracted attack surface element, which is generated by a specific coding rule and contains domain identification, element type identification, and unique serial number, etc., to ensure uniqueness in all domains.
[0065] The attack surface elements in different domains are compared one by one, and the attributes, characteristics and actual meanings of the elements are analyzed. By comparing the unique identifiers corresponding to each element, the matching relationship between the attack surface elements in different domains is determined (such as the association between a certain sensitive data field in the data domain and the business process accessing the data in the business domain). Record and store these cross-domain association relationships to form an association relationship table, which contains the identifiers of attack surface elements in different domains and association types, etc.
[0066] Exemplarily, according to the specific target and requirement of attack surface analysis (such as identifying potential attack paths, evaluating attack risk levels, etc.), the key attributes are selected from the attributes of the attack surface elements as the dimensions of the feature vector. The key attributes need to effectively reflect the core characteristics of the attack surface elements, for example, for the IP address attack surface element, its key attributes may include whether it is a common attack source, the network segment it belongs to, etc.
[0067] The selected key attributes are quantitatively processed. For numerical attributes (such as port number), their numerical values are directly retained; for categorical attributes (such as data access permissions divided into high, medium and low), they are converted into numerical values through a mapping relationship (such as high = 3, medium = 2, low = 1); for text attributes (such as element description), word embedding or other methods are used to convert them into numerical values.
[0068] The quantified features are encoded according to the preset order to form the initial structure of the feature vector. During the encoding process, the position of each feature in the vector must be fixed to ensure consistency during subsequent cross-domain analysis. The encoded numerical features are combined to form the incremental feature vector of each attack surface element in each domain, and are stored in association with the corresponding attack surface element identifier.
[0069] S120, based on the pre-trained Transformer model, the incremental feature vectors of each domain are processed in parallel, the association relationship between the incremental features of each domain is captured, the weight coefficients of each domain increment are assigned, and the association relationship matrix is output.
[0070] In some embodiments, the pre-training process of the Transformer model includes:
[0071] The input history multi-domain incremental data and the attack surface state snapshot are used as a corresponding overall attack surface actual increment as a supervised signal, and a Transformer model is trained in a combination of self-supervised and supervised learning;
[0072] The cross-domain correlation patterns between the multi-domain increments are learned through the self-attention mechanism, the feature representation is optimized through the feedforward neural network, the model parameters are iteratively updated to minimize the error between the predicted increment and the actual increment, and a pre-trained Transformer model is obtained.
[0073] In some embodiments, the pre-trained Transformer model processes the incremental feature vectors of each domain of the parallel input, captures the correlation between the increments of each domain, assigns weight coefficients to each domain increment, and outputs a correlation matrix, including:
[0074] The long-term dependence and nonlinear interaction between the incremental feature vectors in the input sequence are automatically captured based on the self-attention mechanism, and each incremental feature vector is assigned a weight;
[0075] Based on the feedforward neural network, the feature vectors processed by the self-attention mechanism are further nonlinearly transformed, and the transformed feature vectors are integrated to output the correlation matrix.
[0076] In some embodiments, the weight coefficients are dynamically adjusted according to real-time threat intelligence, business scenarios, or model confidence.
[0077] Illustratively, historical multi-domain incremental data is collected, covering incremental data in data domain, network domain, business domain and space-time domain in the past cycles, which needs to include data content and corresponding timestamp information. The attack surface state snapshot of each historical time node is extracted, which needs to record the specific state and correlation of each domain attack surface element at that time. The overall attack surface actual increment corresponding to each historical time period is determined as the supervised signal for model training.
[0078] The combination of self-supervised and supervised learning is adopted. In the self-supervised learning part, data enhancement operations such as masking and shuffling are performed on the historical multi-domain incremental data to let the model learn the internal potential law of the data; in the supervised learning part, the overall attack surface actual increment is used as a label to guide the model to learn prediction.
[0079] The historical multi-domain incremental data and the attack surface state snapshot are input into an initial Transformer model. The model learns the cross-domain association patterns between the multi-domain increments through a self-attention mechanism, calculates the attention weights between the incremental data of different domains, and captures their dependency relationships. A feedforward neural network is used to optimize the feature representation processed by the self-attention mechanism, and the expression ability of the features is improved through nonlinear transformation. The model parameters are iteratively updated by the backpropagation algorithm to minimize the error between the predicted increment and the actual increment. After each iteration, the loss function (such as the mean square error loss function) of the predicted value and the actual value is calculated, and the model's weights and biases are adjusted according to the loss value. The iteration process is repeated until the loss function value stabilizes within a preset threshold range, and the pre-trained Transformer model is obtained.
[0080] Exemplarily, the incremental feature vectors generated by each domain are parallelized and processed, and input into the pre-trained Transformer model in a predetermined order to form an input sequence. The model uses a self-attention mechanism to compare each incremental feature vector in the input sequence with each other, calculates their attention scores, and captures the long-term dependencies and nonlinear interactions between the incremental feature vectors.
[0081] According to the attention scores, each incremental feature vector is assigned a corresponding weight, and the higher the weight, the more important the feature vector is in the overall association relationship. The feature vectors with weights processed by the self-attention mechanism are input into a feedforward neural network for further nonlinear transformation to strengthen the discriminability and expression ability of the feature vectors.
[0082] At the same time, real-time threat intelligence data sources can also be accessed, and when a certain type of threat event is detected frequently, the weight coefficient of the incremental feature vector related to the threat in the domain can be increased. For example, if real-time intelligence shows that network attacks are frequent, the weight of the network domain incremental feature vector can be appropriately increased.
[0083] Different business scenario requirements can also be preset to adjust the weight rules. For example, in the financial business scenario, the security of the data domain and the business domain is more important, and the weight coefficients of the incremental feature vectors of these two domains can be increased.
[0084] The prediction confidence of the model can also be monitored, and when the prediction confidence of a domain incremental feature vector is lower than a preset threshold, the weight coefficient of the domain incremental feature vector can be reduced; otherwise, when the confidence is higher than the threshold, the weight coefficient can be appropriately increased.
[0085] Exemplarily, the domain incremental feature vectors processed by the feedforward neural network and completed weight coefficient dynamic adjustment are integrated and sequentially arranged according to the categories of the domains and the dimensions of the feature vectors. According to the integrated feature vectors and the weight relationships therebetween, a correlation matrix is generated. The rows and columns of the matrix correspond to the incremental feature vectors of the domains respectively, and the element values in the matrix represent the correlation strengths between the corresponding two feature vectors, and the greater the numerical value is, the closer the correlation is. Finally, the generated correlation matrix is output and stored in a designated database for subsequent analysis and application.
[0086] In some embodiments, the incremental feature vectors of the domains are weighted based on the weight coefficients, and the weighted incremental feature vectors of the domains are depth-correlation-constrained and modulated based on the correlation matrix to generate the overall attack surface increment.
[0087] In some embodiments, the incremental feature vectors of the domains are weighted based on the weight coefficients, and the weighted incremental feature vectors of the domains are depth-correlation-constrained and modulated based on the correlation matrix to generate the overall attack surface increment.
[0088]
[0089] wherein, ∆AS(k) is the overall attack surface increment that needs to be updated at time step k; α, β, δ, ε are weight coefficients of the data domain, network domain, service domain, and space-time domain increments respectively; 、 、 and are the data domain increment, network domain increment, service domain increment, and space-time domain increment respectively; γ is a global scaling factor; is a fusion operation; is the correlation matrix output by the Transformer model processing the current context information D.
[0090] Exemplarily, based on the weight coefficients α, β, δ, ε of the data domain, network domain, service domain, and space-time domain increments obtained in S120, the data domain incremental feature vector, network domain incremental feature vector, service domain incremental feature vector, and space-time domain incremental feature vector are respectively multiplied by the respective weight coefficients to obtain the weighted incremental feature vectors of the domains.
[0091] The weighted incremental feature vectors of the domains and the correlation matrix are fused by the fusion operation to realize depth-correlation-constraint and modulation of the weighted incremental feature vectors of the domains.
[0092] S140, the overall attack surface increment is written into the attack surface knowledge base for incremental update, and the Transformer model is continuously fine-tuned based on the incremental update result and the feedback signal of the actual security event.
[0093] Exemplarily, it is checked whether the data format of the generated overall attack surface increment conforms to the storage requirements of the knowledge base, including data types (such as numerical type, vector type), field structure (such as fields containing time step k, increment value, etc.), and the like, and if not, format conversion is performed. The overall attack surface increment that passes the format verification is written into the knowledge base according to the writing rules of the knowledge base (such as append writing, writing according to time step index, etc.), and the incremental update of the knowledge base is completed.
[0094] The actual security event types that need to be collected (such as network attack events, data leakage events, business abnormal access events, etc.) are explicitly required to ensure coverage of various security scenarios related to attack surface. Real-time capture of actual security events by security monitoring devices, extraction of key information of events, including event occurrence time, attack surface elements involved, event impact degree, etc.
[0095] The extracted security event key information is converted into a standardized feedback signal, which needs to be able to reflect the correlation degree between the actual security event and the overall attack surface increment (such as the deviation between the corresponding attack surface increment prediction value and the actual impact when a security event occurs).
[0096] Exemplarily, the latest and historical overall attack surface increment update data from the attack surface knowledge base is extracted, including the overall attack surface increment of each time step and the corresponding domain increment feature vector, weight coefficient, etc.
[0097] The extracted incremental update data is associated and matched with the collected actual security event feedback signal, aligned according to time step, and the fine-tuning training data set of the Transformer model is constructed, wherein the input is the domain increment feature vector and the label is the overall attack surface increment corrected according to the feedback signal (such as the increment value adjusted according to the prediction deviation of the feedback signal).
[0098] The related parameters of model fine-tuning are determined, including learning rate, training rounds, batch size, etc., to avoid overfitting or underfitting of the model. The fine-tuning training data set is input into the pre-trained Transformer model, and the same optimizer as in the pre-training phase is used to minimize the error between the corrected prediction increment and the actual increment (combined with the feedback signal) as the target, and the model parameters are iteratively updated.
[0099] Exemplarily, during the fine-tuning process, the model performance is evaluated periodically using the validation data set, the indicators include prediction error, correlation relationship capture accuracy, etc., if the performance does not reach the preset threshold, the fine-tuning parameters are adjusted (such as increasing the training rounds, adjusting the learning rate) to fine-tune again.
[0100] When the model fine-tuning effect meets the evaluation index requirement, save the fine-tuned Transformer model parameters, replace the original pre-trained model, and use it for subsequent incremental feature vector processing tasks.
[0101] According to the above steps, after generating a new overall attack surface increment and completing the knowledge base update, the collection of actual security event feedback signals and the model fine-tuning process are triggered, forming a closed loop of "incremental update-feedback collection-model fine-tuning", and continuously optimizing the performance of the Transformer model.
[0102] In summary, the present disclosure achieves the following technical effects:
[0103] (1) By extracting attack surface elements and establishing cross-domain associations, the data barriers of each domain are broken down, and effective integration of data is achieved.
[0104] (2) Based on the pre-trained Transformer model, the association between increments of each domain can be effectively captured, and the model is more suitable for the actual scene through the weight dynamic adjustment mechanism. The output association matrix accurately reflects the feature correlation strength.
[0105] Based on the incremental update results and the security event feedback fine-tuned model, the model parameters are continuously optimized, improving the model's ability to capture cross-domain associations and prediction accuracy, and enhancing the model's adaptability in dynamic security environments.
[0106] (3) The overall attack surface increment generated can comprehensively reflect the changes in the security status of each domain, providing accurate basis for security analysis and decision-making. The attack surface knowledge base maintains timeliness and accuracy through incremental updates, combined with the continuously optimized model, forming a complete security protection support system, improving the ability to perceive, analyze and predict attack surfaces, and providing strong technical support for network security protection.
[0107] It should be noted that, for the foregoing method embodiments, in order to simply describe, they are all described as a series of action combinations, but those skilled in the art should know that the present disclosure is not limited by the action sequence described, because according to the present disclosure, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present disclosure.
[0108] The above is an introduction to the method embodiment, and the following will further describe the present disclosure scheme through the device embodiment.
[0109] Figure 2 The structure diagram of the attack surface cross-domain incremental parallel update device based on the Transformer model is shown in FIG. 1. Figure 2As shown, the cross-domain incremental parallel updating apparatus 200 based on the Transformer model can include:
[0110] a feature vector generation module 210, configured to collect incremental data of multiple domains and perform preprocessing, establish a cross-domain unified attack surface element identifier, and convert the incremental data of each domain into vector representation to generate incremental feature vectors of each domain;
[0111] a cross-domain correlation modeling module 220, configured to process the incremental feature vectors of each domain input in parallel based on the pre-trained Transformer model, capture the correlation between the incremental data of each domain, assign weight coefficients to the incremental data of each domain, and output a correlation matrix;
[0112] an overall incremental calculation module 230, configured to weight the incremental feature vectors of each domain based on the weight coefficients, and perform deep correlation constraint and modulation on the weighted incremental feature vectors of each domain based on the correlation matrix to generate an overall attack surface increment;
[0113] a model optimization module 240, configured to write the overall attack surface increment into an attack surface knowledge base for incremental updating, and continuously fine-tune the Transformer model based on the incremental updating result and a feedback signal of an actual security event.
[0114] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the described modules can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0115] In the technical solution of the present disclosure, the acquisition, storage and application of user personal information involved comply with relevant laws and regulations and do not violate public order and good customs.
[0116] According to embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.
[0117] Figure 3 A structural diagram of an exemplary electronic device capable of implementing embodiments of the present disclosure is shown. The electronic device 300 is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device 300 can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present disclosure described and / or claimed in this document.
[0118] As Figure 3As shown, the electronic device 300 can include a computing unit 301 that can perform various appropriate actions and processes in accordance with a computer program stored in a read-only memory (ROM) 302 or a computer program loaded from a storage unit 308 into a random access memory (RAM) 303. Various programs and data required for the operation of the electronic device 300 can also be stored in the RAM 303. The computing unit 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0119] Various components in the electronic device 300 are connected to the I / O interface 305, including an input unit 306, such as a keyboard, a mouse, etc., an output unit 307, such as various types of displays, a speaker, etc., a storage unit 308, such as a magnetic disk, an optical disk, etc., and a communication unit 309, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 309 allows the electronic device 300 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0120] The computing unit 301 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 301 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 301 performs various methods and processes described above, such as the method 100. For example, in some embodiments, the method 100 can be implemented as a computer program product including a computer program tangibly embodied in a computer readable medium, such as the storage unit 308. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 300 via the ROM 302 and / or the communication unit 309. When the computer program is loaded into the RAM 303 and executed by the computing unit 301, one or more steps of the method 100 described above can be performed. Alternatively, in other embodiments, the computing unit 301 can be configured to perform the method 100 by any other appropriate means, such as by means of firmware.
[0121] The various implementations described above can be implemented in digital electronic circuitry, integrated circuitry, specially designed application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0122] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces a means for implementing the functions / acts specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0123] In the context of the present disclosure, a computer-readable medium can be a tangible medium that can contain or store program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0124] It should be noted that the present disclosure also provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to make a computer execute the method 100 and achieve the corresponding technical effects achieved by the embodiments of the present disclosure in executing their methods. For brevity, the description will not be repeated here.
[0125] In addition, the present disclosure also provides a computer program product comprising a computer program which, when executed by a processor, implements the method 100.
[0126] To provide for interaction with a user, the above described embodiments can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0127] The above described embodiments can be implemented in a computing system that includes a back-end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front-end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0128] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server is generally established by computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, a server of a distributed system, or a server combined with a blockchain.
[0129] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from, without departing from the scope of the present disclosure. For example, the steps described in the present disclosure can be executed in parallel, in sequence, or in a different order, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, and the present disclosure is not limited herein.
[0130] The above detailed description does not limit the scope of the disclosure. Various modifications, combinations, sub-combinations and alternatives can be made to the detailed description. Any modification, equivalent replacement and improvement etc. made within the spirit and principle of the disclosure shall be included in the scope of the disclosure.
Claims
1. A method for cross-domain incremental parallel update of the attack surface based on the Transformer model, characterized in that, include: Incremental data from multiple domains are collected and preprocessed to establish a unified cross-domain attack surface element identifier. The incremental data from each domain is then converted into vector representations to generate incremental feature vectors for each domain. The self-attention mechanism is used to automatically capture the long-term dependencies and nonlinear interactions between incremental feature vectors in the input sequence, and to assign weights to each incremental feature vector. The feature vectors processed by the self-attention mechanism are further transformed by a feedforward neural network, and the transformed feature vectors are integrated to output an association matrix. The incremental feature vectors of each domain are weighted based on weighting coefficients, and the weighted incremental feature vectors of each domain are then subjected to deep correlation constraints and modulation based on the correlation matrix to generate the overall attack surface increment. Where ∆AS(k) is the overall attack surface increment that needs to be updated within time step k; α, β, δ, and ε are the weight coefficients of the increments in the data domain, network domain, service domain, and spatiotemporal domain, respectively. , , as well as These represent the data domain increment, network domain increment, service domain increment, and spatiotemporal domain increment, respectively; γ is the global scaling factor. For fusion operation; The relational moments output by the Transformer model after processing the current context information D; The overall attack surface increment is written into the attack surface knowledge base for incremental updates, and the Transformer model is continuously fine-tuned based on the incremental update results and feedback signals from actual security events.
2. The method according to claim 1, characterized in that, The multiple domains include data domain, network domain, business domain, and spatiotemporal domain.
3. The method according to claim 2, characterized in that, The process of establishing a unified cross-domain attack surface element identifier and converting incremental data from each domain into vector representations to generate incremental feature vectors for each domain includes: Potential attack surface elements are extracted from the preprocessed data of each domain, a unique identifier is generated for each attack surface element, and cross-domain associations are established by comparing the attack surface elements and their identifiers in different domains. Based on the goals and requirements of attack surface analysis, key attributes that can effectively reflect the characteristics of attack surface elements are selected as the dimensions of the feature vector. The selected features are then quantified and encoded, and converted into numerical vector representations.
4. The method according to claim 1, characterized in that, The weighting coefficients are dynamically adjusted based on real-time threat intelligence, business scenarios, or model confidence levels.
5. The method according to claim 1, characterized in that, The pre-training process of the Transformer model includes: Input historical multi-domain incremental data and attack surface state snapshots, use the corresponding overall attack surface actual increment as the supervision signal, and train the Transformer model using a combination of self-supervised and supervised learning. By learning cross-domain correlation patterns between multi-domain increments through a self-attention mechanism, optimizing feature representations through a feedforward neural network, and iteratively updating model parameters with the goal of minimizing the error between predicted and actual increments, a pre-trained Transformer model is obtained.
6. A cross-domain incremental parallel update device for attack surface based on the Transformer model, characterized in that, include: The feature vector generation module is used to collect incremental data from multiple domains and preprocess it to establish a unified cross-domain attack surface element identifier, and convert the incremental data of each domain into a vector representation to generate incremental feature vectors for each domain. The cross-domain association modeling module is used to automatically capture the long-term dependencies and nonlinear interactions between incremental feature vectors in the input sequence based on the self-attention mechanism, and to assign weights to each incremental feature vector. The feature vectors processed by the self-attention mechanism are further transformed by a feedforward neural network, and the transformed feature vectors are integrated to output an association matrix. The overall incremental calculation module is used to weight the incremental feature vectors of each domain based on weight coefficients, and to perform deep correlation constraints and modulation on the weighted incremental feature vectors of each domain based on the correlation matrix, thereby generating the overall attack surface increment. Where ∆AS(k) is the overall attack surface increment that needs to be updated within time step k; α, β, δ, and ε are the weight coefficients of the increments in the data domain, network domain, service domain, and spatiotemporal domain, respectively. , , as well as These represent the data domain increment, network domain increment, service domain increment, and spatiotemporal domain increment, respectively; γ is the global scaling factor. For fusion operation; The relational moments output by the Transformer model after processing the current context information D; The model optimization module is used to write the overall attack surface increment into the attack surface knowledge base for incremental updates, and to continuously fine-tune the Transformer model based on the incremental update results and feedback signals from actual security events.
7. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in any one of claims 1-5.
8. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Event merging method and system based on attack surface recognition
CN118784356A
Efficient management of complex attack surfaces
WO2023204973A1