Network attack path prediction method and device based on heterogeneous graph, and medium
By generating real-time heterogeneous graphs and quantum field game models, the real-time performance and multi-source heterogeneous data fusion problems of existing network attack path prediction methods are solved, enabling rapid adaptation to dynamic network environments and efficient attack path prediction.
Patent Information
- Application Number
- CN202511299727.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-09-12
AI Technical Summary
Existing network attack path prediction methods rely on static graph structures, which are difficult to adapt to rapid changes in the network environment. Furthermore, the fusion of multi-source heterogeneous data is challenging, resulting in poor real-time performance and low prediction accuracy.
A network attack path prediction method based on heterogeneous graphs is adopted. By collecting multi-source heterogeneous data, a real-time heterogeneous graph is generated. The TPP framework is used to define node and relationship types. Combined with quantum field game model and quantum tunneling effect, attack path prediction results are generated. Real-time isolation control is achieved through photonic bandgap modulation.
It improves the model's adaptability to dynamic network environments, enhances the accuracy and timeliness of attack path prediction, and effectively reduces the scope and extent of potential threats through quantum isolation signals.
Smart Images

Figure CN120785667B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a network attack path prediction method and device based on heterogeneous graph, and a medium. BACKGROUND
[0002] With the rapid development of information technology, network security threats are becoming increasingly complex and diverse. Researchers have begun to explore the use of graph theory, machine learning and other advanced technologies to build more intelligent defense devices. In particular, in the field of network attack path prediction, using graph data structures to represent network topology and its dynamic changes has become a research hotspot. By modeling network entities and their relationships as nodes and edges in a graph, complex network behavior patterns can be effectively captured, and potential attack paths can be predicted accordingly.
[0003] Although current methods have made significant progress in some aspects, there are still limitations in handling real-time and dynamic changes. First, most existing network attack path prediction models rely on static graph structures, making it difficult to adapt to rapid changes in network environments. Second, the effective integration of multi-source heterogeneous data is also a major challenge. Different data sources may contain different types of information (such as traffic data, log files, etc.), and how to seamlessly integrate these information to provide a more comprehensive attack view is a problem that needs to be solved. SUMMARY
[0004] In view of the above existing problems, the present application is proposed.
[0005] Therefore, the present application provides a network attack path prediction method based on heterogeneous graph to solve the problem of poor real-time performance and low prediction accuracy caused by the reliance on static graph structures and the difficulty of multi-source heterogeneous data integration in the prior art.
[0006] To solve the above technical problems, the present application provides the following technical solutions:
[0007] In a first aspect, the present application provides a network attack path prediction method based on heterogeneous graph, which comprises: collecting multi-source heterogeneous data, extracting basic entities and relationships to generate structured data, defining nodes and relationship types by using a TPP framework, and generating a real-time heterogeneous graph by using a dynamic updating mechanism; generating an attack correlation feature matrix based on the real-time heterogeneous graph and the multi-source heterogeneous data, extracting potential threat features by feature fusion, mining attack correlation paths, and generating an attack path candidate set; constructing a quantum field game model based on the attack path candidate set, generating an evasive path set by combining quantum tunneling effect, and generating a final attack path prediction result and a confidence score by quickly adapting to attacks through double variational optimization; mapping the final attack path prediction result and the confidence score to a physical topology, blocking signals when detecting attack traffic, and generating executable isolation control instructions; collecting intercepted data based on the executable isolation control instructions and calculating a defense success rate tensor, and updating the real-time heterogeneous graph by a knowledge evolution mechanism.
[0008] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph, the real-time heterogeneous graph is generated by the following specific steps,
[0009] The multi-source heterogeneous data is collected, and a multi-source heterogeneous security data set is constructed by multi-modal tensor alignment and missing value compensation.
[0010] The basic entities and relationships are extracted from the multi-source heterogeneous security data set to generate structured data.
[0011] The structured data is input into the TPP framework to define nodes and relationship edges, and the structured data is processed by using a dynamic updating mechanism to adjust the node correlation weight in real time, and a real-time heterogeneous graph is generated.
[0012] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph, the attack correlation feature matrix is generated by the following specific steps,
[0013] The real-time heterogeneous graph is received, a quantum-chaos collaborative tensor is constructed by combining multi-source heterogeneous data flow, a space-time correlation tensor is generated by quantum state superposition and chaotic phase synchronization mechanism.
[0014] The space-time correlation tensor is input into a chaotic harmonic distiller, potential threat features are extracted by multiple logarithmic function compression and time derivative convolution, and an attack correlation feature matrix is generated.
[0015] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph, the attack path candidate set is generated by the following specific steps,
[0016] Perform quantum random walk on the attack correlation feature matrix, calculate the attack path expectation value through the node quantum state encoding, and fuse the chaotic Lagrange quantity to mine the attack correlation path, to generate an attack correlation path set;
[0017] Based on the attack correlation path set, an attack path candidate set is generated through confidence ranking and threat intensity filtering.
[0018] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas, the specific steps of generating the evasive path set are as follows,
[0019] Based on the attack path candidate set, the attacker and defender states are encoded into quantum superposition states, a Hamiltonian of attack-defense coupling is constructed, and a quantum field game model is generated;
[0020] According to the quantum field game model, an evasive path is generated by using quantum tunneling effect, and a threat gradient field potential barrier and tunneling probability integral are calculated to generate an evasive path set.
[0021] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas, the specific steps of generating the final attack path prediction result are as follows
[0022] The evasive path set is input into a double variational optimization mechanism, attack strategy network parameters are updated through a strategy evaluation function, defense discriminator parameters are updated through a quantum entropy regularization term, and an optimized strategy is generated.
[0023] Based on the optimized strategy, Chen-Simon integral and path manifold projection are performed to generate a final attack path prediction result and a confidence score.
[0024] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas, the specific steps of generating the executable isolation control instruction are as follows
[0025] Based on the final attack path prediction result and the confidence score, physical topology mapping parameters are obtained through a dynamic photonic band gap equation, and a photonic band gap regulation instruction is generated.
[0026] In the physical position indicated by the photonic band gap regulation instruction, the network traffic features are detected in real time, and the local threat entropy value is calculated.
[0027] When the local threat entropy value exceeds the path curvature threshold, a quantum Hall edge state blocking mechanism is activated to generate a quantum isolation signal.
[0028] Based on the quantum isolation signal, an executable isolation control instruction is generated through an optoelectronic conversion circuit.
[0029] As a preferred scheme of the network attack path prediction method based on the heterogeneous graph atlas provided in the application, wherein: the executable isolation control instruction is used to collect interception data and calculate a defense success rate tensor, and a real-time heterogeneous graph atlas is updated through a knowledge evolution mechanism, and the specific steps are as follows,
[0030] Based on the executable isolation control instruction, attack interception data is collected, and a quantum state interception data set is constructed.
[0031] Based on the quantum state interception data set, a defense success rate tensor is calculated on a Riemannian manifold to generate a defense success rate parameter.
[0032] Based on the defense success rate parameter, a quantum-topology hybrid knowledge evolution operator is constructed to generate an atlas evolution matrix.
[0033] The atlas evolution matrix is applied to the quantum state representation of the real-time heterogeneous graph atlas, and the node correlation weight is updated through quantum gate operation.
[0034] Based on the updated node correlation weight, the node correlation relationship is reconstructed through a chaotic synchronization differential equation to generate an updated real-time heterogeneous graph atlas.
[0035] In a second aspect, the application provides a computer device, comprising a memory and a processor, and the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the network attack path prediction method based on the heterogeneous graph atlas according to the first aspect of the application is realized.
[0036] In a third aspect, the application provides a computer readable storage medium, which stores a computer program, wherein: when the computer program is executed by the processor, any step of the network attack path prediction method based on the heterogeneous graph atlas according to the first aspect of the application is realized.
[0037] The application has the following beneficial effects: by collecting multi-source heterogeneous data and using multi-modal tensor alignment and missing value compensation mechanism, the ability to adapt to the rapid changes of network environment is realized, not only the ability of the model to cope with dynamic network environment changes is improved, but also the accuracy and timeliness of predicting attack paths are enhanced; according to the attack path candidate set, a game confrontation model is constructed, which can quickly find the best defense strategy when facing the changing attack mode, and effectively reduces the influence range and degree of potential threats. BRIEF DESCRIPTION OF DRAWINGS
[0038] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of these drawings.
[0039] Fig. 1 A flowchart of a network attack path prediction method based on a heterogeneous graph.
[0040] Fig. 2 A flowchart of generating a real-time heterogeneous graph.
[0041] Fig. 3 A flowchart of generating an attack path candidate set.
[0042] Fig. 4 A flowchart of generating an executable isolation control instruction. DETAILED DESCRIPTION
[0043] In order to make the above objectives, features and advantages of the present application more apparent, specific embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0044] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present application. However, it will be apparent to one skilled in the art that the present application can be practiced without the specific details given herein, that the present application can be practiced with other than the described implementations, and that the present application can be practiced with different or additional components. Therefore, the specific details set forth in the following description are by way of examples and not intended to limit the present application.
[0045] Secondly, the "one embodiment" or "embodiment" referred to herein means that the specific features, structures or characteristics can be included in at least one implementation of the present application. The "in one embodiment" appearing in different places in the specification does not mean the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments.
[0046] REFERENCE Figs. 1-4 For one embodiment of the present application, the embodiment provides a network attack path prediction method based on a heterogeneous graph, comprising the following steps:
[0047] S1: Collecting multi-source heterogeneous data, extracting basic entities and relationships to generate structured data, defining nodes and relationship types using the TPP framework, and generating a real-time heterogeneous graph using a dynamic updating mechanism.
[0048] Collecting multi-source heterogeneous data, aligning multi-modal tensors and compensating for missing values to form a multi-source heterogeneous security data set.
[0049] It should be noted that the multi-source heterogeneous data includes network traffic data, security log data, dark web monitoring data, hardware device signal and honeypot interaction information, the timestamp synchronization and feature dimension unification are realized through multi-modal tensor alignment, the missing part is compensated by using a generative adversarial network in the multi-modal tensor alignment process, the generative adversarial network is trained through the adversarial game between the generator and the discriminator, so that the generator learns the high-dimensional probability distribution characteristics of the real data, thereby generating synthetic data consistent with the statistical characteristics of the real data, and the missing value compensation mechanism fills the incomplete data by using the learned high-dimensional probability distribution characteristics, and finally outputs a complete and aligned multi-source heterogeneous security data set.
[0050] The basic entities and relationships are extracted from the multi-source heterogeneous security data set to generate structured data.
[0051] The specific process includes identifying attack source IP, target device ID and vulnerability number as basic entities from the multi-source heterogeneous security data set, detecting communication connection, privilege escalation and data exfiltration as relationship types, mapping the attack source IP to the attacker node, the target device ID to the victim asset node, and the vulnerability number to the attack technology node, mapping the communication connection relationship to the attack initiation edge, the privilege escalation relationship to the vulnerability exploitation edge, and the data exfiltration relationship to the asset impact edge, and finally outputting the structured data containing nodes and edges.
[0052] The structured data is input into the TPP framework to define nodes and relationship edges, and a dynamic updating mechanism is used to process the structured data to adjust the node association weight in real time, and generate a real-time heterogeneous graph.
[0053] The specific process includes converting the attacker node, victim asset node and attack technology node in the structured data into the corresponding node types in the knowledge graph through the TPP framework, converting the attack initiation edge, vulnerability exploitation edge and asset impact edge in the structured data into the corresponding relationship types in the knowledge graph through the TPP framework, and adjusting the connection weight through the dynamic updating mechanism in the conversion process. The threat propagation intensity and path dependence relationship between nodes determine the path dependence relationship between nodes, which is determined by the historical attack mode and the current network state, and the weight adjustment result is fed back to the edge attribute in the knowledge graph in real time. Finally, a real-time heterogeneous graph containing the latest node state and relationship weight is output.
[0054] S2: Based on the real-time heterogeneous graph and multi-source heterogeneous data, an attack correlation feature matrix is generated, and potential threat features are extracted through feature fusion to mine attack correlation paths and generate an attack path candidate set.
[0055] The real-time heterogeneous graph is received, combined with the multi-source heterogeneous data stream to construct a quantum-chaos collaborative tensor, and through the quantum state superposition and chaos phase synchronization mechanism, a space-time correlation tensor is generated.
[0056] The specific process includes: embedding node state vectors into the node attributes and adjacency relationships in the real-time heterogeneous graph using a graph neural network; constructing a quantum-chaotic cooperative tensor by tensor product operations using the node state vectors and network traffic data, security log data, dark web monitoring data, and hardware device signals from multi-source heterogeneous data streams; extracting key attack pattern features from the quantum state components in the quantum-chaotic cooperative tensor using the Grover search algorithm; coherently superimposing the probability amplitudes of different attack paths to form a global threat situation using the quantum state superposition process; deriving the threat propagation trajectory using the Lorenz attractor equation; and using a chaotic phase synchronization mechanism to keep the node state synchronized with network threat fluctuations by adjusting the coupling coefficient. Finally, a spatiotemporal correlation tensor containing spatiotemporal correlation features is output. The row vectors in the spatiotemporal correlation tensor represent the threat correlation strength of nodes in the spatiotemporal dimension, and the column vectors represent the spatiotemporal propagation patterns of attack paths.
[0057] Key attack pattern features refer to dynamic rule sequences extracted from multi-source heterogeneous data that can reveal the correlation between cross-platform attack behaviors and have a high threat confidence.
[0058] The spatiotemporal correlation tensor is input into a chaotic resonant distiller, and potential threat features are extracted through multilogarithmic function compression and time derivative convolution to generate an attack correlation feature matrix.
[0059] The specific process includes: extracting features from the spatiotemporal dimension data in the spatiotemporal correlation tensor using a chaotic resonant distiller; applying a multi-logarithmic function transformation to the spatiotemporal correlation tensor to achieve data compression and feature enhancement; and then performing time derivative convolution to capture the dynamic change patterns of threat features. During the time derivative convolution operation, a Gaussian kernel function is used to smooth noise interference and retain effective signals. The final output attack correlation feature matrix has row vectors representing the threat intensity distribution of different attack paths and column vectors representing the pattern sequence of threat feature evolution over time.
[0060] A quantum random walk is performed on the attack correlation feature matrix. The expected value of the attack path is calculated through node quantum state encoding, and the attack correlation path is mined by incorporating chaotic Lagrange quantities to generate a set of attack correlation paths, expressed as:
[0061] ;
[0062] in, Indicates the first The expected value of each attack path. The sequence number representing the attack path. The initial quantum state representing the starting point information of the attack path. This represents the conjugate transpose of the quantum evolution operator. This indicates the conjugate transpose. Indicates the first The expected value of each attack path. This represents the quantum evolution operator.
[0063] The specific process includes obtaining node features based on multi-source heterogeneous data streams through feature extraction and standardization. The node features are then converted into initial quantum states through quantum state encoding. The initial quantum states undergo quantum random walk evolution through quantum evolution operators. During the evolution process, the expected value of each attack path is calculated. The expected value calculation of the attack path adopts the principle of quantum projection measurement. The quantum projection measurement results are fused and analyzed with chaotic Lagrange quantities. The chaotic Lagrange quantities are used to mine hidden correlations between paths through nonlinear dynamic equations, and finally, a set of attack correlation paths containing high-threat paths is generated.
[0064] Chaotic Lagrangian is a dynamic functional that characterizes the nonlinear propagation of network attacks, integrating quantum state evolution and chaotic attractor properties through variational principles.
[0065] Based on the set of attack-related paths, a candidate set of attack paths is generated by ranking by confidence and filtering by threat intensity.
[0066] The specific process includes: each path in the attack-related path set is first sorted in descending order according to the expected value of the path to generate a confidence ranking list; the path data in the confidence ranking list is filtered by a preset threat strength threshold; during the filtering process, paths with confidence higher than the quantum path confidence threshold and meeting the chaotic threat strength standard are retained; and the final output attack path candidate set contains effective attack paths with high confidence and high threat strength.
[0067] It should be noted that the path data in the confidence ranking list is a set of attack path features generated during the quantum-chaos co-analysis process, containing dual features of quantum state probability amplitude and chaotic dynamic parameters.
[0068] The preset threat strength threshold is dynamically generated based on the attack success rate and impact of the historical attack pattern database, and is dynamically adjusted according to the historical attack pattern database.
[0069] The historical attack pattern database is a knowledge base of attack behaviors built from real network attack data accumulated over a long period of time, through multimodal feature extraction and spatiotemporal correlation analysis.
[0070] The quantum path confidence threshold is dynamically generated based on the statistical distribution of expected values of historical attack paths and current network situational awareness data. Specifically, the critical value is determined by a linear combination of the mean and standard deviation obtained through a sliding window algorithm.
[0071] The chaos threat intensity standard is established based on nonlinear dynamics characteristics of network attack behaviors and quantum-chaos coupling effects, and a multidimensional evaluation system is obtained by training historical attack data.
[0072] S3: Based on the attack path candidate set, a quantum field game model is constructed, combined with quantum tunneling effect, an evasive path set is generated, and through double variational optimization, the attack is quickly adapted to generate the final attack path prediction result and confidence score.
[0073] Based on the attack path candidate set, the attacker and defender states are encoded as quantum superposition states, a Hamiltonian of attack-defense coupling is constructed, and a quantum field game model is generated.
[0074] The specific process includes: the attacker behavior characteristics in the attack path candidate set are extracted by analyzing the abnormal connection mode between path nodes, attack payload characteristics and lateral movement trajectory, the defense strategy characteristics are generated according to the security policy type deployed on the defense path, interception record and response timeliness, the attacker behavior characteristics in the attack path candidate set are converted into attacker quantum superposition state through quantum state coding, the defense strategy characteristics in the attack path candidate set are converted into defender quantum superposition state through quantum state coding, the attacker quantum superposition state and the defender quantum superposition state are constructed into an attack-defense joint state space through tensor product operation, the interaction in the attack-defense joint state space is mathematically described by the Hamiltonian of exchange term and coupling term, the exchange term in the Hamiltonian simulates the strategy change process of the attacker, the coupling term in the Hamiltonian quantifies the mutual influence strength of the strategies of the attack and defense sides, and finally the generated quantum field game model completely characterizes the quantum dynamics evolution law of attack-defense confrontation.
[0075] According to the quantum field game model, the evasive path is generated using quantum tunneling effect, and the threat gradient field potential barrier and tunneling probability integral are obtained to generate the evasive path set.
[0076] The specific process includes: the attack-defense state potential energy distribution in the quantum field game model obtains the characteristic energy spectrum through the eigenvalue problem of the Schrödinger equation, the gradient distribution of the characteristic energy spectrum forms the threat gradient field potential barrier, the energy level structure of the threat gradient field potential barrier generates potential evasive paths through quantum tunneling effect analysis, the WKB approximation method is used in the quantum tunneling effect analysis process to generate the tunneling probability integral and obtain the path tunneling probability value, the tunneling probability integral result filters out the effective paths with path tunneling probability value higher than the path tunneling probability threshold, and finally the output evasive path set contains all the hidden attack paths discovered through quantum tunneling effect.
[0077] The path tunneling probability threshold is generated by the Boltzmann distribution function according to the energy eigenvalue distribution in the quantum field game model and the statistical law of historical attack success rate.
[0078] The evasion path set is input into the dual variational optimization mechanism, the attack strategy network parameters are updated through the strategy evaluation function, and the defense discriminator parameters are updated through the quantum entropy regularization term to generate an optimized strategy.
[0079] The specific process includes inputting the evasion path set into the dual variational optimization mechanism, the strategy evaluation function in the dual variational optimization mechanism deriving the attack effect score of each path and updating the attack strategy network parameters, the quantum entropy regularization term in the dual variational optimization mechanism measuring the chaos degree of the path distribution and updating the defense discriminator parameters, and the cooperative optimization process of the attack strategy network parameters and the defense discriminator parameters generating an optimized strategy adapting to the latest threat situation.
[0080] The strategy evaluation function is constructed through the adversarial training process of the quantum generative adversarial network, and the strategy evaluation function maps the quantum state features of the attack path into attack effect score values.
[0081] The attack strategy network parameters refer to the weight matrix quantifying the attack behavior features, which are optimized through the training process of the generative adversarial network on the historical attack data set.
[0082] The defense discriminator parameters refer to the feature weight matrix quantifying the defense strategy effectiveness, which is dynamically optimized through the adversarial training process of the quantum generative adversarial network on real-time threat detection data.
[0083] Based on the optimized strategy, the Chen-Simmons integral and path manifold projection are performed to generate the final attack path prediction result and confidence score.
[0084] The specific process includes obtaining the topological features in the optimized strategy through the Chen-Simmons integral, the Chen-Simmons integral process using the connection form in the gauge field theory to perform a surface integral on a three-dimensional manifold, extracting the curvature features of the path through the surface integral result, and mapping the curvature features to the observable attack path space through path manifold projection. The path manifold projection process preserves the integrity of the topological features and uses Riemannian geometry to reduce high-dimensional features to the actual network path space, finally generating the final attack path prediction result and confidence score containing specific node sequences and attack steps.
[0085] S4: Map the final attack path prediction result and confidence score to the physical topology, and perform signal blocking when detecting attack traffic to generate executable isolation control instructions.
[0086] Based on the final attack path prediction result and confidence score, the physical topology mapping parameters are obtained through the dynamic photonic band gap equation, and the photonic band gap control instructions are generated.
[0087] The specific process includes inputting node position information and confidence score in the final attack path prediction result into a dynamic photonic band gap equation, adjusting the photonic crystal structure parameters according to the node position information and the confidence score, converting the wavelength adjustment amount output by the dynamic photonic band gap equation into physical topology mapping parameters through a nonlinear optical-topology mapping function, specifying the position and adjustment amplitude that need to be adjusted in the photonic crystal array through the physical topology mapping parameters, generating photonic band gap regulation instructions according to the physical topology mapping parameters, and the photonic band gap regulation instructions containing specific wavelength offset values and action time parameters.
[0088] The photonic crystal structure parameters are derived from the intrinsic physical properties and manufacturing process specifications of the photonic crystal material and are determined in advance through quantum electromagnetic field simulation and energy band structure.
[0089] In the physical position indicated by the photonic band gap regulation instruction, the network traffic characteristics are detected in real time, and the local threat entropy value is calculated, and the expression is:
[0090] ;
[0091] Among them, represents the local threat entropy value, represents the total number of threat feature types, represents the index number of the threat feature type, represents the probability of the occurrence of the class threat feature.
[0092] The specific process includes that the monitoring unit deployed at the physical position specified in the photonic band gap regulation instruction collects network traffic data packets in real time, obtains the statistical count of various threat features through protocol analysis and feature extraction, converts the threat feature statistical count into a probability distribution, and inputs it into the Shannon entropy formula to obtain the local threat entropy value, which represents the uncertainty and complexity of the network threat at the physical position indicated by the photonic band gap regulation instruction.
[0093] When the local threat entropy value exceeds the path curvature threshold value, the quantum Hall edge state blocking mechanism is activated, and a quantum isolation signal is generated.
[0094] The specific process includes comparing the local threat entropy monitoring result with the preset path curvature threshold value, triggering the quantum Hall effect activation condition when the local threat entropy exceeds the path curvature threshold value, starting the edge state conductive channel of the topological insulator material after the quantum Hall effect activation condition is met, generating the one-way transmission quantum Hall edge state current by the edge state conductive channel of the topological insulator material, generating the changing magnetic flux by the time-varying magnetic field in the nanoring resonator, exciting the induced electromotive force by the Faraday electromagnetic induction law, driving the quantumized conductance by the topologically protected one-way conductive channel, generating the quantum isolation signal by the Josephson effect modulation microwave photon, and the quantum isolation signal contains the encryption blocking instruction with the quantum unclonable characteristic.
[0095] The path curvature threshold value is dynamically generated according to the attack path geometric characteristics in the historical attack mode library, and is a critical value that is adjusted in real time through the theory of spatiotemporal chaos.
[0096] Based on the quantum isolation signal, an executable isolation control instruction is generated through an optoelectronic conversion circuit.
[0097] The specific process includes converting the quantum isolation signal into an analog electrical signal through a photodiode in the optoelectronic conversion circuit, amplifying the analog electrical signal into a measurable voltage signal through a transimpedance amplifier, quantizing the measurable voltage signal into a digital signal through an analog-to-digital converter, inputting the digital signal into an instruction compiling unit to parse an operation code and a parameter segment, defining the isolation action type by the operation code, and containing the target device identifier and the execution time parameter in the parameter segment, and finally generating the executable isolation control instruction.
[0098] S5: Based on the executable isolation control instruction, intercept data is collected and a defense success rate tensor is calculated, and a real-time heterogeneous graph is updated through a knowledge evolution mechanism.
[0099] Based on the executable isolation control instruction, attack interception data is collected, and a quantum state interception data set is constructed.
[0100] The specific process includes that the executable isolation control instruction drives the network sensor to capture the data packet in the attack interception process, the data packet in the attack interception process is converted into a quantum state form through a quantum encoder, the data packet in the quantum state form is associated with attack path information through the quantum entanglement characteristic, the attack path information and the real-time interception state obtained by the network sensor jointly constitute the ground state component of the quantum state interception data set, and the ground state component forms the complete quantum state interception data set through quantum superposition.
[0101] Based on the quantum state interception data set, a defense success rate tensor is calculated on a Riemannian manifold to generate a defense success rate parameter, and the expression is:
[0102] ;
[0103] in, The tensor representing the defense success rate. Indicates the length of the observation time window. Represents a time variable. Indicates at a point in time The measure of defensive effectiveness. This represents the historical maximum metric value. Indicates the curvature weighting coefficient. Represents the path curvature feature. This represents the historical maximum curvature value.
[0104] The specific process includes modeling the spatiotemporal event distribution in the quantum state interception dataset using a metric structure on a Riemannian manifold. The metric structure is constructed by integrating the defense effectiveness strength metric within a time window. The integration result is weighted and fused with the path curvature feature. During the weighted fusion process, the historical maximum metric value and the historical maximum curvature value are used for normalization. The normalized result is used to generate a defense success rate tensor through tensor synthesis. The defense success rate tensor is used to extract the final defense success rate parameter through feature value extraction.
[0105] The historical maximum metric value is a benchmark reference value obtained by recording the highest value that occurs throughout the entire observation history through long-term monitoring of the defense effectiveness strength metric.
[0106] The historical maximum curvature value is obtained by continuously recording the geometric curvature of all attack paths and selecting the highest curvature value as the benchmark reference value.
[0107] A quantum-topological hybrid knowledge evolution operator is constructed based on the defense success rate parameter to generate a graph evolution matrix.
[0108] The specific process includes: inputting the defense success rate parameter into the quantum-topological hybrid knowledge evolution operator construction process; the quantum-topological hybrid knowledge evolution operator constructs evolution rules by combining quantum entanglement properties and topological invariants; the quantum component in the evolution rules is determined by the probability amplitude of the defense success rate parameter, and the topological component is determined by the curvature characteristics of the attack path; the quantum component and the topological component are fused into a hybrid evolution rule through tensor product operation; the hybrid evolution rule acts on the current knowledge graph state to generate a graph evolution matrix; the graph evolution matrix contains node relationship update weights and topological structure adjustment parameters.
[0109] The graph evolution matrix is applied to the quantum state representation of the real-time heterogeneous graph, and the node association weights are updated through quantum gate operations.
[0110] The specific process includes: the atlas evolution matrix is subjected to tensor contraction operation with the quantum state representation of the real-time heterogeneous atlas, the tensor contraction operation result is adjusted by a controlled rotation gate in quantum gate operation to adjust the correlation strength weight between nodes, the updating process of the correlation strength weight adopts quantum amplitude amplification technology to enhance the significant threat connection, and finally the output node correlation weight reflects the latest attack path topology structure.
[0111] Based on the updated node correlation weight, the node correlation relationship is reconstructed by a chaotic synchronization differential equation to generate an updated real-time heterogeneous atlas.
[0112] The specific process includes: the updated node correlation weight is input into the chaotic synchronization differential equation, the chaotic synchronization differential equation describes the attractor dynamic characteristics of the node correlation weight through a nonlinear function, the synchronization stability condition of the attractor dynamic characteristics determines the evolution convergence direction of the node correlation strength through the Lyapunov index, and the evolution convergence result of the node correlation strength generates a new adjacency relationship matrix through a matrix reconstruction algorithm, and the new adjacency relationship matrix and the original node correlation weight are combined to generate an updated real-time heterogeneous atlas.
[0113] The embodiment also provides a computer device suitable for the network attack path prediction method based on a heterogeneous atlas, including: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the network attack path prediction method based on a heterogeneous atlas proposed in the above embodiment.
[0114] The computer device can be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device. In addition, the input device can be an external keyboard, touchpad or mouse, etc.
[0115] The embodiment also provides a storage medium on which a computer program is stored, the program being executed by a processor to implement the method for predicting a network attack path based on a heterogeneous graph as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk.
[0116] To sum up, the application has the ability to adapt to the rapid changes of the network environment by collecting multi-source heterogeneous data and using a multi-modal tensor alignment and missing value compensation mechanism, which not only improves the ability of the model to cope with dynamic network environment changes, but also enhances the accuracy and timeliness of the predicted attack path; the game confrontation model is constructed according to the attack path candidate set, which can quickly find the best defense strategy when facing the changing attack mode, and effectively reduces the influence range and degree of potential threats.
[0117] It should be noted that the above embodiments are only used to illustrate the technical solutions of the application rather than limit the application. Although the application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the application, which should be covered in the scope of the claims of the application.
Claims
1. A network attack path prediction method based on heterogeneous graphs, characterized in that: include, The process involves collecting multi-source heterogeneous data, extracting basic entities and relationships to generate structured data, defining node and relationship types using the TPP framework, and employing a dynamic update mechanism to generate a real-time heterogeneous graph. The specific steps are as follows: Collect multi-source heterogeneous data, and construct a multi-source heterogeneous secure dataset through multimodal tensor alignment and missing value compensation; Extract basic entities and relationships from multi-source heterogeneous security datasets to generate structured data; Structured data is input into the TPP framework to define nodes and relation edges, and a dynamic update mechanism is used to process the structured data, adjust the node association weights in real time, and generate a real-time heterogeneous graph. Based on real-time heterogeneous maps and multi-source heterogeneous data, an attack association feature matrix is generated, and potential threat features are extracted through feature fusion to mine attack association paths and generate a candidate set of attack paths. A quantum field game model is constructed based on the attack path candidate set. Combined with the quantum tunneling effect, an evasion path set is generated. The model is then rapidly adapted to the attack through dual variational optimization to generate the final attack path prediction result and confidence score. The final attack path prediction results and confidence scores are mapped to the physical topology, and signal blocking is performed when attack traffic is detected, generating executable isolation control instructions; Based on executable isolation control commands, interception data is collected and the defense success rate tensor is calculated. The real-time heterogeneous graph is updated through a knowledge evolution mechanism.
2. The network attack path prediction method based on heterogeneous graphs as described in claim 1, characterized in that: The specific steps for generating the attack-related feature matrix are as follows: Receive real-time heterogeneous spectra, combine multi-source heterogeneous data streams to construct a quantum-chaotic cooperative tensor, and generate a spatiotemporal correlation tensor through quantum state superposition and chaotic phase synchronization mechanism; The spatiotemporal correlation tensor is input into a chaotic resonant distiller, and potential threat features are extracted through multilogarithmic function compression and time derivative convolution to generate an attack correlation feature matrix.
3. The network attack path prediction method based on heterogeneous graphs as described in claim 2, characterized in that: The specific steps for generating the attack path candidate set are as follows: A quantum random walk is performed on the attack correlation feature matrix, the expected value of the attack path is calculated by the node quantum state encoding, and the attack correlation path is mined by the chaotic Lagrange multiplier to generate a set of attack correlation paths. Based on the set of attack-related paths, a candidate set of attack paths is generated by ranking by confidence and filtering by threat intensity.
4. The network attack path prediction method based on heterogeneous graphs as described in claim 3, characterized in that: The specific steps for generating the set of avoidance paths are as follows. Based on the attack path candidate set, the states of the attacker and defender are encoded as quantum superposition states, and a Hamiltonian coupled with the attack and defense is constructed to generate a quantum field game model. Based on the quantum field game model, the quantum tunneling effect is used to generate avoidance paths, and the threat gradient field barrier and tunneling probability integral are calculated to generate a set of avoidance paths.
5. The network attack path prediction method based on heterogeneous graphs as described in claim 4, characterized in that: The specific steps for generating the final attack path prediction result and confidence score are as follows: The set of evasion paths is input into a dual variational optimization mechanism. The attack policy network parameters are updated through the policy evaluation function, and the defense discriminator parameters are updated through the quantum entropy regularization term to generate an optimized policy. Based on the optimization strategy, the Chen-Simons integral and path manifold projection are performed to generate the final attack path prediction results and confidence scores.
6. The network attack path prediction method based on heterogeneous graphs as described in claim 5, characterized in that: The specific steps for generating executable isolation control instructions are as follows: Based on the final attack path prediction results and confidence scores, physical topology mapping parameters are obtained through the dynamic photonic bandgap equation, and photonic bandgap control commands are generated. At the physical location indicated by the photonic bandgap modulation command, network traffic characteristics are detected in real time, and local threat entropy values are calculated. When the local threat entropy exceeds the path curvature threshold, the quantum Hall edge state blocking mechanism is activated, generating a quantum isolation signal. Based on quantum isolation signals, executable isolation control commands are generated through photoelectric conversion circuits.
7. The network attack path prediction method based on heterogeneous graphs as described in claim 6, characterized in that: The specific steps for collecting interception data based on executable isolation control commands, calculating the defense success rate tensor, and updating the real-time heterogeneous graph through a knowledge evolution mechanism are as follows. Based on executable isolation control commands, attack interception data is collected, and a quantum state interception dataset is constructed. Based on the quantum state interception dataset, the defense success rate tensor is calculated on the Riemannian manifold to generate defense success rate parameters; A quantum-topological hybrid knowledge evolution operator is constructed based on the defense success rate parameter to generate a graph evolution matrix; The graph evolution matrix is applied to the quantum state representation of the real-time heterogeneous graph, and the node association weights are updated through quantum gate operations; Based on the updated node association weights, the node association relationships are reconstructed through chaotic synchronization differential equations to generate an updated real-time heterogeneous graph.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the network attack path prediction method based on heterogeneous graphs as described in any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the network attack path prediction method based on heterogeneous graphs as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Network traceability data processing method, system, equipment and medium
CN120342751A
Management and control method, device and equipment for network attack of digital power grid, storage medium and program product
CN120498762A