Heterogeneous atlas-based network attack path prediction method and device, and medium

Through a network attack path prediction method based on heterogeneous graphs, multi-source heterogeneous data is used to generate real-time dynamic graphs. Combined with quantum field game models and photonic bandgap regulation, the problem of difficulty in fusing static graph structures and multi-source heterogeneous data in existing technologies is solved, and efficient network attack path prediction and defense are achieved.

CN120785667AActive Publication Date: 2025-10-14JIANGSU ELECTRIC POWER INFORMATION TECH

Patent Information

Application Number
CN202511299727.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-12
Publication Date
2025-10-14
Estimated Expiration
2045-09-12

AI Technical Summary

Technical Problem

Existing network attack path prediction methods rely on static graph structures, which are difficult to adapt to the rapid changes in the network environment. In addition, it is difficult to fuse multi-source heterogeneous data, resulting in poor real-time performance and low prediction accuracy.

Method used

A network attack path prediction method based on heterogeneous graphs is adopted. By collecting multi-source heterogeneous data, a real-time dynamic heterogeneous graph is generated. The TPP framework is used to define node and relationship types. Combined with the quantum field game model and quantum tunneling effect, the attack path prediction results are generated, and network isolation is achieved through photonic band gap regulation.

Benefits of technology

The model's adaptability to dynamic network environments has been improved, the accuracy and timeliness of attack path predictions have been enhanced, and the optimal defense strategy can be quickly found to reduce the scope and extent of potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785667A_ABST
    Figure CN120785667A_ABST
Patent Text Reader

Abstract

The invention discloses a heterogeneous atlas-based network attack path prediction method and device and a medium, and relates to the technical field of network security, and the method comprises the following steps: collecting multi-source heterogeneous data, extracting basic entities and relationships to generate structured data, defining nodes and relationship types by using a TPP framework, and generating a real-time heterogeneous atlas by using a dynamic update mechanism; based on the real-time dynamic heterogeneous atlas and the multi-source heterogeneous data, generating an attack association feature matrix, extracting potential threat features through feature fusion, mining attack association paths, and generating an attack path candidate set; constructing a quantum field game model based on the attack path candidate set, generating an evasion path set in combination with a quantum tunneling effect, quickly adapting to attacks through dual variational optimization, and generating a final attack path prediction result and a confidence score; according to the method, the game confrontation model is constructed through the attack path candidate set, and the optimal defense strategy can be quickly found in the face of continuously changing attack modes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a network attack path prediction method and device based on heterogeneous graph, and a medium. BACKGROUND

[0002] With the rapid development of information technology, network security threats are becoming increasingly complex and diverse. Researchers have begun to explore the use of graph theory, machine learning and other advanced technologies to build more intelligent defense devices. In particular, in the field of network attack path prediction, using graph data structures to represent network topology and its dynamic changes has become a research hotspot. By modeling network entities and their relationships as nodes and edges in a graph, complex network behavior patterns can be effectively captured, and potential attack paths can be predicted accordingly.

[0003] Although current methods have made significant progress in some aspects, there are still limitations in handling real-time and dynamic changes. First, most existing network attack path prediction models rely on static graph structures, making it difficult to adapt to rapid changes in network environments. Second, the effective integration of multi-source heterogeneous data is also a major challenge. Different data sources may contain different types of information (such as traffic data, log files, etc.), and how to seamlessly integrate these information to provide a more comprehensive attack view is a problem that needs to be solved. SUMMARY

[0004] In view of the above existing problems, the present application is proposed.

[0005] Therefore, the present application provides a network attack path prediction method based on heterogeneous graph to solve the problem of poor real-time performance and low prediction accuracy caused by the reliance on static graph structures and the difficulty of multi-source heterogeneous data integration in the prior art.

[0006] To solve the above technical problems, the present application provides the following technical solutions:

[0007] In a first aspect, the present application provides a network attack path prediction method based on heterogeneous graph, which comprises: collecting multi-source heterogeneous data, extracting basic entities and relationships to generate structured data, defining nodes and relationship types by using a TPP framework, and generating a real-time heterogeneous graph by using a dynamic updating mechanism; generating an attack correlation feature matrix based on the real-time dynamic heterogeneous graph and the multi-source heterogeneous data, extracting potential threat features by feature fusion, mining attack correlation paths, and generating an attack path candidate set; constructing a quantum field game model based on the attack path candidate set, generating an evasive path set by combining quantum tunneling effect, and generating a final attack path prediction result and a confidence score by quickly adapting to attacks through double variational optimization; mapping the final attack path prediction result and the confidence score to a physical topology, blocking signals when detecting attack traffic, and generating executable isolation instructions; collecting intercepted data based on the executable isolation control instructions, calculating a defense success rate tensor, and updating the real-time heterogeneous graph by a knowledge evolution mechanism.

[0008] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph, the real-time heterogeneous graph is generated by the following specific steps,

[0009] The multi-source heterogeneous data is collected, and a multi-source heterogeneous security data set is constructed by multi-modal tensor alignment and missing value compensation.

[0010] The basic entities and relationships are extracted from the multi-source heterogeneous security data set to generate structured data.

[0011] The structured data is input into the TPP framework to define nodes and relationship edges, and the structured data is processed by using a dynamic updating mechanism to adjust the node correlation weight in real time, thereby generating a real-time heterogeneous graph.

[0012] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph, the attack correlation feature matrix is generated by the following specific steps,

[0013] The real-time heterogeneous graph is received, a quantum-chaos collaborative tensor is constructed by combining a multi-source heterogeneous data stream, a spatiotemporal correlation tensor is generated by using a quantum state superposition and a chaotic phase synchronization mechanism.

[0014] The spatiotemporal correlation tensor is input into a chaotic harmonic distiller, potential threat features are extracted by using a multiple logarithmic function compression and a time derivative convolution, and an attack correlation feature matrix is generated.

[0015] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph, the attack path candidate set is generated by the following specific steps,

[0016] Perform quantum random walk on the attack correlation feature matrix, calculate the attack path expectation value through the node quantum state encoding, and fuse the chaotic Lagrange quantity to mine the attack correlation path, to generate an attack correlation path set;

[0017] Based on the attack correlation path set, an attack correlation path candidate set is generated through confidence ranking and threat intensity filtering.

[0018] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas, the specific steps of generating the evasive path set are as follows,

[0019] Based on the attack path candidate set, the attacker and defender states are encoded into quantum superposition states, the Hamiltonian of attack-defense coupling is constructed, and a quantum field game model is generated;

[0020] According to the quantum field game model, the evasive path is generated by using the quantum tunneling effect, and the threat gradient field potential barrier and tunneling probability integral are calculated to generate the evasive path set.

[0021] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas, the specific steps of generating the final attack path prediction result are as follows,

[0022] The evasive path set is input into the double variational optimization mechanism, the attack strategy network parameters are updated through the strategy evaluation function, the defense discriminator parameters are updated through the quantum entropy regularization term, and the optimized strategy is generated.

[0023] Based on the optimized strategy, the Chen-Simon integral and path manifold projection are performed to generate the final attack path prediction result and the confidence score.

[0024] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas, the specific steps of generating the executable isolation instruction are as follows,

[0025] Based on the final attack path prediction result and the confidence score, the physical topology mapping parameters are obtained through the dynamic photonic band gap equation, and the photonic band gap control instruction is generated;

[0026] In the physical position indicated by the photonic band gap control instruction, the network traffic features are detected in real time, and the local threat entropy value is calculated;

[0027] When the local threat entropy value exceeds the path curvature threshold, the quantum Hall edge state blocking mechanism is activated to generate a quantum isolation signal;

[0028] Based on the quantum isolation signal, an executable isolation control instruction is generated through an optoelectronic conversion circuit.

[0029] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas provided in the application, wherein: the executable isolation control instruction is used to collect interception data and calculate a defense success rate tensor, and a real-time heterogeneous graph atlas is updated through a knowledge evolution mechanism, and the specific steps are as follows,

[0030] Based on the executable isolation control instruction, attack interception data is collected, and a quantum state interception data set is constructed.

[0031] Based on the quantum state interception data set, a defense success rate tensor is calculated on a Riemannian manifold to generate a defense success rate parameter.

[0032] Based on the defense success rate parameter, a quantum-topology hybrid knowledge evolution operator is constructed to generate an atlas evolution matrix.

[0033] The atlas evolution matrix is applied to the quantum state representation of the real-time heterogeneous graph atlas, and the node correlation weight is updated through quantum gate operation.

[0034] Based on the updated node correlation weight, the node correlation relationship is reconstructed through a chaotic synchronization differential equation to generate an updated real-time heterogeneous graph atlas.

[0035] In a second aspect, the application provides a computer device, comprising a memory and a processor, and the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the network attack path prediction method based on the heterogeneous graph atlas according to the first aspect of the application is realized.

[0036] In a third aspect, the application provides a computer readable storage medium, which stores a computer program, wherein: when the computer program is executed by the processor, any step of the network attack path prediction method based on the heterogeneous graph atlas according to the first aspect of the application is realized.

[0037] The application has the following beneficial effects: by collecting multi-source heterogeneous data and using multi-modal tensor alignment and missing value compensation mechanism, the ability to adapt to the rapid changes of network environment is realized, not only the ability of the model to cope with dynamic network environment changes is improved, but also the accuracy and timeliness of predicting attack paths are enhanced; according to the attack path candidate set, a game confrontation model is constructed, which can quickly find the best defense strategy when facing the changing attack mode, and effectively reduces the influence range and degree of potential threats. BRIEF DESCRIPTION OF DRAWINGS

[0038] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of these drawings.

[0039] Fig. 1 Flowchart of the network attack path prediction method based on heterogeneous graph.

[0040] Fig. 2 Flowchart for generating real-time heterogeneous graphs.

[0041] Fig. 3 Flowchart for generating attack path candidate sets.

[0042] Fig. 4 A flowchart for generating executable isolated instructions. DETAILED DESCRIPTION

[0043] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0044] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0045] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.

[0046] Reference Figs. 1-4 , is an embodiment of the present invention, which provides a network attack path prediction method based on a heterogeneous graph, comprising the following steps:

[0047] S1: Collect multi-source heterogeneous data, extract basic entities and relationships to generate structured data, use the TPP framework to define node and relationship types, and adopt a dynamic update mechanism to generate a real-time heterogeneous graph.

[0048] Collect multi-source heterogeneous data and construct a multi-source heterogeneous security dataset through multi-modal tensor alignment and missing value compensation.

[0049] It should be noted that the multi-source heterogeneous data includes network traffic data, security log data, dark web monitoring data, hardware device signal and honeypot interaction information, the timestamp synchronization and feature dimension unification are realized through multi-modal tensor alignment, the missing part is compensated by using a generative adversarial network in the multi-modal tensor alignment process, the generative adversarial network is trained through the adversarial game between the generator and the discriminator, so that the generator learns the high-dimensional probability distribution characteristics of the real data, thereby generating synthetic data consistent with the statistical characteristics of the real data, and the missing value compensation mechanism fills the incomplete data by using the learned high-dimensional probability distribution characteristics, and finally outputs a complete and aligned multi-source heterogeneous security data set.

[0050] The basic entities and relationships are extracted from the multi-source heterogeneous security data set to generate structured data.

[0051] The specific process includes identifying attack source IP, target device ID and vulnerability number as basic entities from the multi-source heterogeneous security data set, detecting communication connection, privilege escalation and data exfiltration as relationship types, mapping the attack source IP to the attacker node, the target device ID to the victim asset node, and the vulnerability number to the attack technology node, mapping the communication connection relationship to the attack initiation edge, the privilege escalation relationship to the vulnerability exploitation edge, and the data exfiltration relationship to the asset impact edge, and finally outputting structured data containing nodes and edges.

[0052] The structured data is input into the TPP framework to define nodes and relationship edges, and a dynamic updating mechanism is used to process the structured data to adjust the node association weight in real time, and generate a real-time heterogeneous graph.

[0053] The specific process includes converting the attacker node, victim asset node and attack technology node in the structured data into the corresponding node types in the knowledge graph through the TPP framework, converting the attack initiation edge, vulnerability exploitation edge and asset impact edge in the structured data into the corresponding relationship types in the knowledge graph through the TPP framework, and adjusting the connection weight through the dynamic updating mechanism in the conversion process. The threat propagation intensity and path dependence relationship between nodes determine the path dependence relationship between nodes, which is determined by the historical attack mode and the current network state, and the weight adjustment result is fed back to the edge attribute in the knowledge graph in real time. Finally, a real-time heterogeneous graph containing the latest node state and relationship weight is output.

[0054] S2: Based on the real-time dynamic heterogeneous graph and multi-source heterogeneous data, an attack correlation feature matrix is generated, and potential threat features are extracted through feature fusion to mine attack correlation paths and generate an attack path candidate set.

[0055] The real-time heterogeneous graph is received, combined with the multi-source heterogeneous data stream to construct a quantum-chaos collaborative tensor, and through the quantum state superposition and chaos phase synchronization mechanism, a space-time correlation tensor is generated.

[0056] The specific process includes embedding the node attributes and adjacency relationships in the real-time heterogeneous graph through graph neural networks to obtain the node state vector, and constructing the quantum-chaos synergy tensor through tensor product operations on the node state vector and the network traffic data, security log data, dark web monitoring data and hardware device signals in the multi-source heterogeneous data stream. The quantum state components in the quantum-chaos synergy tensor are extracted through the Grover search algorithm to extract key attack mode features. The quantum state superposition process coherently superimposes the probability amplitudes of different attack paths to form a global threat situation, and derives the threat propagation trajectory through the Lorenz attractor equation. The chaotic phase synchronization mechanism synchronizes the node state with the network threat fluctuations by adjusting the coupling coefficient, and finally outputs a spatiotemporal correlation tensor containing spatiotemporal correlation characteristics. The row vectors in the spatiotemporal correlation tensor represent the threat correlation strength of the node in the spatiotemporal dimension, and the column vectors represent the spatiotemporal propagation pattern of the attack path.

[0057] Key attack pattern features refer to dynamic rule sequences extracted from multi-source heterogeneous data that can reveal the correlation of cross-platform attack behaviors and have high threat confidence.

[0058] The spatiotemporal correlation tensor is input into the chaotic resonance distiller, and the potential threat features are extracted through multi-logarithmic function compression and time derivative convolution to generate the attack correlation feature matrix.

[0059] The specific process includes extracting features from the spatiotemporal dimension data in the spatiotemporal correlation tensor through a chaotic resonance distiller, which applies multi-logarithmic function transformation to the spatiotemporal correlation tensor to achieve data compression and feature enhancement. The tensor data after multi-logarithmic function transformation is then subjected to a time derivative convolution operation to capture the dynamic change pattern of threat characteristics. During the time derivative convolution operation, a Gaussian kernel function is used to smooth noise interference and retain valid signals. The row vectors of the attack correlation feature matrix finally output represent the threat intensity distribution of different attack paths, and the column vectors represent the pattern sequence of threat characteristics evolving over time.

[0060] A quantum random walk is performed on the attack correlation feature matrix. The expected value of the attack path is calculated by encoding the node quantum state. The chaotic Lagrangian is then integrated to mine the attack correlation path and generate an attack correlation path set. The expression is:

[0061] ;

[0062] in, Indicates the The expected value of the attack path, Indicates the sequence number of the attack path, The initial quantum state representing the starting point of the attack path, represents the conjugate transpose of the quantum evolution operator, represents the conjugate transpose, Indicates the The expected value of the attack path, represents the quantum evolution operator.

[0063] The specific process includes obtaining node features after feature extraction and standardization based on multi-source heterogeneous data streams, converting node features into initial quantum states through quantum state encoding, and evolving the initial quantum states through quantum random walks using quantum evolution operators. During the evolution process, the expected value of each attack path is calculated. The expected value of the attack path is calculated using the quantum projection measurement principle. The quantum projection measurement results are fused and analyzed with the chaotic Lagrangian. The chaotic Lagrangian uses nonlinear dynamic equations to explore hidden associations between paths, and ultimately generates a set of attack-related paths containing high-threat paths.

[0064] The chaotic Lagrangian is a dynamic functional that describes the nonlinear propagation law of network attacks. It integrates the evolution of quantum states and the characteristics of chaotic attractors through the variational principle.

[0065] Based on the attack correlation path set, the attack correlation path candidate set is generated through confidence sorting and threat intensity filtering.

[0066] The specific process includes: each path in the attack-related path set is first arranged in descending order according to the path expectation value to generate a confidence-sorted list; the path data in the confidence-sorted list is filtered through a preset threat intensity threshold; during the filtering process, only those paths with confidence higher than the quantum path confidence threshold and meeting the chaos threat intensity standard are retained; the final output attack-related path candidate set contains effective attack paths with high confidence and high threat intensity.

[0067] It should be noted that the path data in the confidence ranking list is a set of attack path features generated during the quantum-chaos collaborative analysis process, which contains the dual features of quantum state probability amplitude and chaotic dynamics parameters.

[0068] The preset threat intensity threshold is dynamically generated based on the attack success rate and impact level in the historical attack pattern library, and is dynamically adjusted based on the historical attack pattern library.

[0069] The historical attack pattern library is an attack behavior knowledge base constructed through long-term accumulation of real network attack data, multimodal feature extraction and spatiotemporal correlation analysis.

[0070] The quantum path confidence threshold is dynamically generated based on the expected value statistical distribution of historical attack paths and current network situational awareness data. Specifically, the critical value is determined by a linear combination of the mean and standard deviation obtained through a sliding window algorithm.

[0071] The chaos threat intensity standard is established based on nonlinear dynamics characteristics of network attack behaviors and quantum-chaos coupling effects, and a multidimensional evaluation system is obtained by training historical attack data.

[0072] S3: Based on the attack path candidate set, a quantum field game model is constructed, combined with quantum tunneling effect, an evasive path set is generated, and through double variational optimization, the attack is quickly adapted to generate the final attack path prediction result and confidence score.

[0073] Based on the attack path candidate set, the attacker and defender states are encoded as quantum superposition states, a Hamiltonian of attack-defense coupling is constructed, and a quantum field game model is generated.

[0074] The specific process includes: the attacker behavior characteristics in the attack path candidate set are extracted by analyzing the abnormal connection mode between path nodes, attack payload characteristics and lateral movement trajectory, the defense strategy characteristics are generated according to the security policy type deployed on the defense path, interception record and response timeliness, the attacker behavior characteristics in the attack path candidate set are converted into attacker quantum superposition state through quantum state coding, the defense strategy characteristics in the attack path candidate set are converted into defender quantum superposition state through quantum state coding, the attacker quantum superposition state and the defender quantum superposition state are constructed into an attack-defense joint state space through tensor product operation, the interaction in the attack-defense joint state space is mathematically described by the Hamiltonian of exchange term and coupling term, the exchange term in the Hamiltonian simulates the strategy change process of the attacker, the coupling term in the Hamiltonian quantifies the mutual influence strength of the strategies of the attack and defense sides, and finally the generated quantum field game model completely characterizes the quantum dynamics evolution law of attack-defense confrontation.

[0075] According to the quantum field game model, the evasive path is generated using quantum tunneling effect, and the threat gradient field potential barrier and tunneling probability integral are obtained to generate the evasive path set.

[0076] The specific process includes: the attack-defense state potential energy distribution in the quantum field game model obtains the characteristic energy spectrum through the eigenvalue problem of the Schrödinger equation, the gradient distribution of the characteristic energy spectrum forms the threat gradient field potential barrier, the energy level structure of the threat gradient field potential barrier generates potential evasive paths through quantum tunneling effect analysis, the WKB approximation method is used in the quantum tunneling effect analysis process to generate the tunneling probability integral and obtain the path tunneling probability value, the tunneling probability integral result filters out the effective paths with path tunneling probability value higher than the path tunneling probability threshold, and finally the output evasive path set contains all the hidden attack paths discovered through quantum tunneling effect.

[0077] The path tunneling probability threshold is generated by the Boltzmann distribution function according to the energy eigenvalue distribution in the quantum field game model and the statistical law of historical attack success rate.

[0078] The evasion path set is input into the dual variational optimization mechanism, the attack strategy network parameters are updated through the strategy evaluation function, and the defense discriminator parameters are updated through the quantum entropy regularization term to generate an optimized strategy.

[0079] The specific process includes inputting the evasion path set into the dual variational optimization mechanism, the strategy evaluation function in the dual variational optimization mechanism deriving the attack effect score of each path and updating the attack strategy network parameters, the quantum entropy regularization term in the dual variational optimization mechanism measuring the chaos degree of the path distribution and updating the defense discriminator parameters, and the cooperative optimization process of the attack strategy network parameters and the defense discriminator parameters generating an optimized strategy adapting to the latest threat situation.

[0080] The strategy evaluation function is constructed through the adversarial training process of the quantum generative adversarial network, and the strategy evaluation function maps the quantum state features of the attack path into attack effect score values.

[0081] The attack strategy network parameters refer to the weight matrix quantifying the attack behavior features, which are optimized through the training process of the generative adversarial network on the historical attack data set.

[0082] The defense discriminator parameters refer to the feature weight matrix quantifying the defense strategy effectiveness, which is dynamically optimized through the adversarial training process of the quantum generative adversarial network on real-time threat detection data.

[0083] Based on the optimized strategy, the Chen-Simmons integral and path manifold projection are performed to generate the final attack path prediction result and confidence score.

[0084] The specific process includes obtaining the topological features in the optimized strategy through the Chen-Simmons integral, the Chen-Simmons integral process using the connection form in the gauge field theory to perform a surface integral on a three-dimensional manifold, extracting the curvature features of the path through the surface integral result, and mapping the curvature features to the observable attack path space through path manifold projection. The path manifold projection process preserves the integrity of the topological features and uses Riemannian geometry to reduce high-dimensional features to the actual network path space, finally generating the final attack path prediction result and confidence score containing specific node sequences and attack steps.

[0085] S4: Map the final attack path prediction result and confidence score to the physical topology, and perform signal blocking when detecting attack traffic to generate executable isolation instructions.

[0086] Based on the final attack path prediction result and confidence score, the physical topology mapping parameters are obtained through the dynamic photonic band gap equation, and the photonic band gap control instructions are generated.

[0087] The specific process includes inputting node position information and confidence score in the final attack path prediction result into a dynamic photonic band gap equation, adjusting the photonic crystal structure parameters according to the node position information and the confidence score, converting the wavelength adjustment amount output by the dynamic photonic band gap equation into physical topology mapping parameters through a nonlinear optical-topology mapping function, specifying the position and adjustment amplitude that need to be adjusted in the photonic crystal array through the physical topology mapping parameters, generating photonic band gap regulation instructions according to the physical topology mapping parameters, and the photonic band gap regulation instructions containing specific wavelength offset values and action time parameters.

[0088] The photonic crystal structure parameters are derived from the intrinsic physical properties and manufacturing process specifications of the photonic crystal material and are determined in advance through quantum electromagnetic field simulation and energy band structure.

[0089] In the physical position indicated by the photonic band gap regulation instruction, the network traffic characteristics are detected in real time, and the local threat entropy value is calculated, and the expression is:

[0090] ;

[0091] Among them, represents the local threat entropy value, represents the total number of threat feature types, represents the index number of the threat feature type, represents the probability of the occurrence of the class threat feature.

[0092] The specific process includes that the monitoring unit deployed at the physical position specified in the photonic band gap regulation instruction collects network traffic data packets in real time, obtains the statistical count of various threat features through protocol analysis and feature extraction, converts the threat feature statistical count into a probability distribution, and inputs it into the Shannon entropy formula to obtain the local threat entropy value, which represents the uncertainty and complexity of the network threat at the physical position indicated by the photonic band gap regulation instruction.

[0093] When the local threat entropy value exceeds the path curvature threshold value, the quantum Hall edge state blocking mechanism is activated, and a quantum isolation signal is generated.

[0094] The specific process includes comparing the local threat entropy monitoring result with the preset path curvature threshold value, triggering the quantum Hall effect activation condition when the local threat entropy exceeds the path curvature threshold value, starting the edge state conduction channel of the topological insulator material after the quantum Hall effect activation condition is met, generating the one-way transmission quantum Hall edge state current by the edge state conduction channel of the topological insulator material, generating the changing magnetic flux by the time-varying magnetic field in the nanoring resonator, exciting the induced electromotive force by the Faraday electromagnetic induction law, driving the quantumized conductance by the topologically protected one-way conduction channel, generating the quantum isolation signal by the Josephson effect modulation microwave photon, and the quantum isolation signal contains the encryption blocking instruction with the quantum unclonable characteristic.

[0095] The path curvature threshold value is dynamically generated according to the attack path geometric characteristics in the historical attack mode library, and is a critical value that is adjusted in real time through the theory of spatiotemporal chaos.

[0096] Based on the quantum isolation signal, an executable isolation control instruction is generated through an optoelectronic conversion circuit.

[0097] The specific process includes converting the quantum isolation signal into an analog electrical signal through a photodiode in the optoelectronic conversion circuit, amplifying the analog electrical signal into a measurable voltage signal through a transimpedance amplifier, quantizing the measurable voltage signal into a digital signal through an analog-to-digital converter, inputting the digital signal into an instruction compiling unit to parse an operation code and a parameter segment, defining the isolation action type by the operation code, and containing the target device identifier and the execution time parameter in the parameter segment, and finally generating the executable isolation control instruction.

[0098] S5: Based on the executable isolation control instruction, intercept data is collected and a defense success rate tensor is calculated, and a real-time heterogeneous graph is updated through a knowledge evolution mechanism.

[0099] Based on the executable isolation control instruction, attack interception data is collected, and a quantum state interception data set is constructed.

[0100] The specific process includes driving the network sensor to capture the data packet in the attack interception process by the executable isolation control instruction, converting the data packet in the attack interception process into a quantum state form by a quantum encoder, associating the attack path information by the quantum state form data packet through the quantum entanglement characteristic, and combining the attack path information and the real-time interception state obtained by the network sensor to form the ground state component of the quantum state interception data set, and forming the complete quantum state interception data set by the ground state component through quantum superposition.

[0101] Based on the quantum state interception data set, a defense success rate tensor is calculated on a Riemannian manifold to generate a defense success rate parameter, and the expression is:

[0102] ;

[0103] in, represents the defense success rate tensor, represents the length of the observation time window, represents the time variable, Indicates at a point in time The defense effectiveness strength measurement value, Indicates the historical maximum metric value, represents the curvature weight coefficient, represents the path curvature characteristic, Indicates the historical maximum curvature value.

[0104] The specific process includes modeling the spatiotemporal event distribution in the quantum state interception dataset through the metric structure on the Riemann manifold. The metric structure is constructed by the integral operation of the defense effectiveness intensity measurement value within the time window. The integral operation result is weightedly fused with the path curvature characteristic. During the weighted fusion process, the historical maximum metric value and the historical maximum curvature value are used for normalization. The normalized result is generated through tensor synthesis operation to generate a defense success rate tensor. The defense success rate tensor obtains the final defense success rate parameter through eigenvalue extraction.

[0105] The historical maximum metric value is a benchmark reference value obtained by long-term monitoring of the defense effectiveness intensity measurement value and recording the highest value that appears in the entire observation history.

[0106] The historical maximum curvature value is obtained by continuously recording the geometric curvature of all attack paths and selecting the highest curvature value as the benchmark reference value.

[0107] A quantum-topological hybrid knowledge evolution operator is constructed based on the defense success rate parameter to generate a graph evolution matrix.

[0108] The specific process includes: the defense success rate parameter is input into the quantum-topological hybrid knowledge evolution operator construction process; the quantum-topological hybrid knowledge evolution operator constructs the evolution rule by combining the quantum entanglement characteristics and topological invariants; the quantum component in the evolution rule is determined by the probability amplitude of the defense success rate parameter, and the topological component is determined by the curvature characteristics of the attack path; the quantum component and the topological component are fused into a hybrid evolution rule through tensor product operation; the hybrid evolution rule acts on the current knowledge graph state to generate a graph evolution matrix; the graph evolution matrix contains node relationship update weights and topological structure adjustment parameters.

[0109] The graph evolution matrix is ​​applied to the quantum state representation of the real-time heterogeneous graph, and the node association weights are updated through quantum gate operations.

[0110] The specific process includes: the atlas evolution matrix is subjected to tensor contraction operation with the quantum state representation of the real-time heterogeneous atlas, the tensor contraction operation result is adjusted by a controlled rotation gate in quantum gate operation to adjust the correlation strength weight between nodes, the updating process of the correlation strength weight adopts quantum amplitude amplification technology to enhance the significant threat connection, and finally the output node correlation weight reflects the latest attack path topology structure.

[0111] Based on the updated node correlation weight, the node correlation relationship is reconstructed by a chaotic synchronization differential equation to generate an updated real-time heterogeneous atlas.

[0112] The specific process includes: the updated node correlation weight is input into the chaotic synchronization differential equation, the chaotic synchronization differential equation describes the attractor dynamic characteristics of the node correlation weight through a nonlinear function, the synchronization stability condition of the attractor dynamic characteristics determines the evolution convergence direction of the node correlation strength through the Lyapunov index, and the evolution convergence result of the node correlation strength generates a new adjacency relationship matrix through a matrix reconstruction algorithm, and the new adjacency relationship matrix and the original node correlation weight are combined to generate an updated real-time heterogeneous atlas.

[0113] The embodiment also provides a computer device suitable for the network attack path prediction method based on a heterogeneous atlas, including: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the network attack path prediction method based on a heterogeneous atlas proposed in the above embodiment.

[0114] The computer device can be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device. In addition, the input device can be an external keyboard, touchpad or mouse, etc.

[0115] The embodiment also provides a storage medium on which a computer program is stored, the program being executed by a processor to implement the method for predicting a network attack path based on a heterogeneous graph as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk.

[0116] To sum up, the application has the ability to adapt to the rapid changes of the network environment by collecting multi-source heterogeneous data and using a multi-modal tensor alignment and missing value compensation mechanism, which not only improves the ability of the model to cope with dynamic network environment changes, but also enhances the accuracy and timeliness of the predicted attack path; the game confrontation model is constructed according to the attack path candidate set, which can quickly find the best defense strategy when facing the changing attack mode, and effectively reduces the influence range and degree of potential threats.

[0117] It should be noted that the above embodiments are only used to illustrate the technical solutions of the application rather than limit the application. Although the application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the application, which should be covered in the scope of the claims of the application.

Claims

1. A network attack path prediction method based on heterogeneous graphs, characterized by: include, Collect multi-source heterogeneous data, extract basic entities and relationships to generate structured data, use the TPP framework to define node and relationship types, and adopt a dynamic update mechanism to generate real-time heterogeneous graphs; Based on real-time dynamic heterogeneous graphs and multi-source heterogeneous data, an attack correlation feature matrix is ​​generated. Through feature fusion, potential threat features are extracted, attack correlation paths are mined, and a candidate set of attack paths is generated. A quantum field game model is constructed based on the attack path candidate set. Combined with the quantum tunneling effect, a set of evasion paths is generated. The model then quickly adapts to the attack through dual variational optimization to generate the final attack path prediction result and confidence score. Map the final attack path prediction results and confidence scores to the physical topology, block signals when detecting attack traffic, and generate executable isolation instructions; Based on executable isolation control instructions, interception data is collected and the defense success rate tensor is calculated, and the real-time heterogeneous graph is updated through the knowledge evolution mechanism.

2. The network attack path prediction method based on heterogeneous graph according to claim 1, characterized in that: The specific steps of generating a real-time heterogeneous graph are as follows: Collect multi-source heterogeneous data and construct a multi-source heterogeneous security dataset through multi-modal tensor alignment and missing value compensation; Extract basic entities and relationships from multi-source heterogeneous security datasets to generate structured data; The structured data is input into the TPP framework to define nodes and relationship edges, and a dynamic update mechanism is used to process the structured data, adjust the node association weights in real time, and generate a real-time heterogeneous graph.

3. The network attack path prediction method based on heterogeneous graph according to claim 2, characterized in that: The specific steps of generating the attack correlation feature matrix are as follows: Receive real-time heterogeneous graphs, combine multi-source heterogeneous data streams to build quantum-chaos synergy tensors, and generate spatiotemporal correlation tensors through quantum state superposition and chaotic phase synchronization mechanisms; The spatiotemporal correlation tensor is input into the chaotic resonance distiller, and the potential threat features are extracted through multi-logarithmic function compression and time derivative convolution to generate the attack correlation feature matrix.

4. The network attack path prediction method based on heterogeneous graph according to claim 3, characterized in that: The specific steps of generating the attack path candidate set are as follows: A quantum random walk is performed on the attack correlation feature matrix. The expected value of the attack path is calculated through node quantum state encoding. The chaotic Lagrangian is then integrated to mine the attack correlation path and generate an attack correlation path set. Based on the attack correlation path set, the attack correlation path candidate set is generated through confidence sorting and threat intensity filtering.

5. The network attack path prediction method based on heterogeneous graph according to claim 4, characterized in that: The specific steps of generating the avoidance path set are as follows: Based on the candidate set of attack paths, the attacker and defender states are encoded into quantum superposition states, the attack-defense coupled Hamiltonian is constructed, and a quantum field game model is generated; According to the quantum field game model, the quantum tunneling effect is used to generate avoidance paths, and the threat gradient field barrier and tunneling probability integral are calculated to generate a set of avoidance paths.

6. The network attack path prediction method based on heterogeneous graph according to claim 5, characterized in that: The specific steps for generating the final attack path prediction result and confidence score are as follows: The set of evasion paths is input into the dual variational optimization mechanism, the attack strategy network parameters are updated through the strategy evaluation function, and the defense discriminator parameters are updated through the quantum entropy regularization term to generate an optimized strategy. Based on the optimization strategy, Chern-Simons integration and path manifold projection are performed to generate the final attack path prediction results and confidence scores.

7. The network attack path prediction method based on heterogeneous graph according to claim 6, characterized in that: The specific steps of generating executable isolation instructions are as follows: Based on the final attack path prediction results and confidence scores, the physical topology mapping parameters are obtained through the dynamic photonic bandgap equation, and photonic bandgap control instructions are generated; At the physical location indicated by the photonic bandgap control instruction, network traffic characteristics are detected in real time, and the local threat entropy value is calculated; When the local threat entropy exceeds the path curvature threshold, the quantum Hall edge state blocking mechanism is activated to generate a quantum isolation signal; Based on the quantum isolation signal, executable isolation control instructions are generated through the photoelectric conversion circuit.

8. The network attack path prediction method based on heterogeneous graph according to claim 7, characterized in that: The interception data is collected based on the executable isolation control instruction, the defense success rate tensor is calculated, and the real-time heterogeneous graph is updated through the knowledge evolution mechanism. The specific steps are as follows: Based on executable isolation control instructions, attack interception data is collected and a quantum state interception data set is constructed; Based on the quantum state interception dataset, the defense success rate tensor is calculated on the Riemannian manifold to generate the defense success rate parameter; Based on the defense success rate parameter, a quantum-topological hybrid knowledge evolution operator is constructed to generate a graph evolution matrix. Apply the graph evolution matrix to the quantum state representation of the real-time heterogeneous graph and update the node association weights through quantum gate operations; Based on the updated node association weights, the node association relationship is reconstructed through chaotic synchronization differential equations to generate an updated real-time heterogeneous graph.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network attack path prediction method based on heterogeneous graphs according to any one of claims 1 to 8 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network attack path prediction method based on heterogeneous graphs according to any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Non-cooperative network attack tracing method based on multiple stages

    CN119854031A

  • Computer network security detection system and method

    CN120281505A

  • Network traceability data processing method, system, equipment and medium

    CN120342751A

  • Network attack path prediction method and system based on knowledge graph

    CN120434050A

  • Management and control method, device and equipment for network attack of digital power grid, storage medium and program product

    CN120498762A

Cited By

  • Honeynet-based attack trapping and analyzing method and system

    CN121619174A

  • Active security defense system and method based on reinforcement learning and attack intention inference

    CN121727864A

  • Active security defense system and method based on reinforcement learning and attack intention inference

    CN121727864B

  • Lightweight attack path generation method and system for power network

    CN121770911A