一种基于攻击阶段语义对齐的异构事件关联表征模型构建方法、系统及设备

By constructing a heterogeneous event association representation model based on the ATT&CK framework and a large language model, the semantic gap problem of heterogeneous security logs is solved, enabling complete reconstruction and efficient tracing of multi-step attack processes.

CN120811708BActive Publication Date: 2026-07-17XI AN JIAOTONG UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XI AN JIAOTONG UNIV
Filing Date
2025-08-01
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively integrate heterogeneous security logs at the network and host levels, and cannot automatically and comprehensively correlate multi-source heterogeneous security logs, making it difficult to fully reconstruct multi-step attack processes and heavily reliant on manual analysis.

Method used

By extracting hexagram and octet features, abnormal log fragment sequences and sensitive behavior log fragment sequences are constructed from inter-host and intra-host logs. Based on the ATT&CK framework and large language model, semantic alignment is performed to construct a heterogeneous event association representation model.

Benefits of technology

It enables a more comprehensive and complete reconstruction of the multi-step attack process, significantly improving the accuracy of attack behavior identification and event correlation, reducing the complexity of manual analysis, and improving the efficiency of attack tracing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005529967320000101
    Figure BDA0005529967320000101
  • Figure BDA0005529967320000111
    Figure BDA0005529967320000111
  • Figure BDA0005529967320000121
    Figure BDA0005529967320000121
Patent Text Reader

Abstract

本发明提供的一种基于攻击阶段语义对齐的异构事件关联表征模型构建方法、系统及设备,包括以下步骤:从获取的主机间连接日志中提取六元组特征,得到统一表征的主机间告警日志数据;基于主机间告警日志数据构建主机间异常日志片段序列;将主机间异常日志片段序列进行映射,得到主机间攻击阶段;从获取的主机内操作日志中提取八元组特征,得到统一表征的主机内操作日志数据;基于主机内操作日志数据构建主机内敏感行为日志片段序列;将主机内敏感行为日志片段映射进行映射,得到主机内攻击阶段;在异构安全事件语义对齐的基础上,将主机间攻击阶段与主机内攻击阶段按照拓扑特征进行关联,构建得到异构事件关联表征模型;本发明能够有效克服单一日志源存在的观测盲区,能够同时捕获网络扫描、漏洞利用等网络行为和脚本执行、权限提升等主机内活动,从而实现对多步攻击过程更全面、更完整的还原。
Need to check novelty before this filing date? Find Prior Art