Attack evidence chain generation method for business risk control and related device

By acquiring and associating target features and evidence information from alarm information within a security protection system, and using an artificial intelligence model to generate attack evidence chains, the problem of low attack tracing efficiency in existing technologies is solved, achieving more efficient and accurate generation of attack evidence chains and enhancing protection capabilities.

CN120979899BActive Publication Date: 2026-04-28BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING VOLCANO ENGINE TECH CO LTD
Filing Date
2025-08-28
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing security systems struggle to quickly correlate and integrate multi-source, heterogeneous attack traces during attack attribution, resulting in low efficiency and incompleteness in extracting attack evidence chains, thus impacting protection capabilities.

Method used

By acquiring target features from alarm information, determining their correlations, and obtaining evidence information, an attack evidence chain is generated. Suspicious features are automatically extracted and correlated using artificial intelligence models, and a complete attack evidence chain is formed by combining rich evidence information.

Benefits of technology

It improves the attack tracing capabilities of the security protection system, enhances the protection capabilities of the protection system, and improves the efficiency and accuracy of attack evidence chain generation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979899B_ABST
    Figure CN120979899B_ABST
Patent Text Reader

Abstract

The present disclosure provides an attack evidence chain generation method and related device for business risk control, the attack evidence chain generation method comprising: obtaining first alarm information; extracting a plurality of target features from the first alarm information, and determining the association relationship between the plurality of target features; obtaining evidence information associated with the plurality of target features; and generating an attack evidence chain corresponding to the first alarm information according to the plurality of target features, the association relationship between the plurality of target features, and the evidence information associated with the plurality of target features. The attack evidence chain generation method can form a complete and accurate attack evidence chain, improve the attack tracing capability of a security protection system such as a cloud security protection product, a security intelligent agent, and further enhance the protection capability of the security protection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a method for generating an attack evidence chain for business risk control, an apparatus for generating an attack evidence chain for business risk control, an electronic device, and a computer-readable storage medium. Background Technology

[0002] With the continuous development of cloud computing technology, security protection systems for cloud security testing have emerged. These systems can include products such as cloud security centers and cloud workload protection platforms (CWPP) that protect workloads in cloud environments.

[0003] With the development of large-scale model technology, security protection systems can also provide security detection services in the form of security intelligent agents. Security intelligent agents are comprehensive intelligent security applications built on large-scale security models and various security tools / plugins. Depending on the capabilities of the tools / plugins and the security model, they can perform various security tasks.

[0004] Security systems can detect and analyze alarm information. During this analysis, security systems typically need to perform attack attribution, for example, extracting attack traces related to the attack from the alarm information to form a chain of attack evidence. Summary of the Invention

[0005] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0006] At least one embodiment of this disclosure provides a method for generating an attack evidence chain for business risk control, comprising: acquiring first alarm information; extracting multiple target features from the first alarm information; and determining the correlation between the multiple target features, wherein the multiple target features include operational behavior and at least one of the following: an object associated with the operational behavior, a time node corresponding to the operational behavior, an associated behavior of the object, and a time node corresponding to the associated behavior; acquiring evidence information associated with the multiple target features; and generating an attack evidence chain corresponding to the first alarm information based on the multiple target features, the correlation between the multiple target features, and the evidence information associated with the multiple target features, wherein the attack evidence chain includes: attack evidence corresponding to each attack node in the attack chain corresponding to the first alarm information.

[0007] At least another embodiment of this disclosure provides an attack evidence chain generation device for business risk control, comprising: a first acquisition module configured to acquire first alarm information; a processing module configured to extract multiple target features from the first alarm information and determine the correlation between the multiple target features, wherein the multiple target features include operational behavior and at least one of the following: an object associated with the operational behavior, a time node corresponding to the operational behavior, an associated behavior of the object, and a time node corresponding to the associated behavior; a second acquisition module configured to acquire evidence information associated with the multiple target features; and a generation module configured to generate an attack evidence chain corresponding to the first alarm information based on the multiple target features, the correlation between the multiple target features, and the evidence information associated with the multiple target features, wherein the attack evidence chain includes attack evidence corresponding to each attack node in the attack chain corresponding to the first alarm information.

[0008] At least one further embodiment of this disclosure provides an electronic device, including: a processing device; and a storage device including one or more computer program instructions; wherein the one or more computer program instructions are executed by the processing device to perform the attack evidence chain generation method for business risk control provided in at least one embodiment of this disclosure.

[0009] At least one further embodiment of this disclosure provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the attack evidence chain generation method for business risk control provided in at least one embodiment of this disclosure.

[0010] At least one embodiment of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the attack evidence chain generation method for business risk control provided in at least one embodiment of this disclosure. Attached Figure Description

[0011] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0012] Figure 1 This illustration schematically depicts an application scenario of a security protection system provided by at least one embodiment of the present disclosure;

[0013] Figure 2 The illustration shows a flowchart of an attack evidence chain generation method for business risk control provided in at least one embodiment of the present disclosure.

[0014] Figure 3 The illustration shows a flowchart of a method for obtaining evidence information provided in at least one embodiment of the present disclosure;

[0015] Figure 4 The schematic diagram illustrates the structure of an attack evidence chain generation device for business risk control according to at least one embodiment of this disclosure; and

[0016] Figure 5 A schematic diagram of the structure of an electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation

[0017] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0018] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0019] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0020] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0021] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0022] The names of the messages or information exchanged between the various devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0023] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0024] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization from relevant users should be obtained. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.

[0025] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly indicate that the operation requested by the user will require obtaining and using the user's information. This allows the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of any embodiment of the present disclosure based on the prompt message.

[0026] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.

[0027] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0028] With the continuous development of cloud computing technology, security protection systems for cloud security testing have emerged. These systems can perform multi-faceted security testing across various operational scenarios. For example, a security protection system can be a cloud workload protection platform (CWPP), which can test host security and network security. Another example is a host-based intrusion detection system (HIDS), which can perform security testing on the behavior and state of computer systems. Yet another example is an endpoint detection and response (EDR) system, which can perform security testing on the system-level behavior of endpoints. Finally, a security protection system can be a container security platform (CSP), which provides multi-faceted security testing for containers.

[0029] With the development of large-scale model technology, artificial intelligence-driven agents have been widely used. These agents are typically able to perceive information in their environment, make decisions, and take actions to achieve specific goals or tasks. For example, in the field of security detection, security protection systems can also provide security detection services in the form of security agents. These security agents are comprehensive intelligent security applications built upon large-scale security models and various security tools / plugins. Depending on the capabilities of the tools / plugins and the security model, they can perform various security tasks.

[0030] The security protection system can detect alarm information, analyze the alarm information, and feed back the alarm analysis results to the user (such as security operations personnel) so that the user can handle the alarm based on the alarm analysis results.

[0031] During the alarm analysis process of a security protection system, it is usually necessary to trace the source of the attack. For example, the attack traces related to the attack can be extracted from the alarm information to form an attack evidence chain.

[0032] However, as attack methods become more covert and complex, an attack may have characteristics such as long duration, multiple stages, and cross-platform nature. Attack traces are scattered in multi-source heterogeneous information such as log information, traffic data, and system configuration information. Security protection systems have difficulty quickly associating and integrating attack traces, resulting in low efficiency and insufficient completeness in the extraction of attack evidence chains, which affects the protection capabilities of security protection systems.

[0033] To address at least some of the aforementioned technical problems, at least one embodiment of this disclosure provides a method for generating an attack evidence chain for business risk control, comprising: acquiring first alarm information; extracting multiple target features from the first alarm information; and determining the correlation between the multiple target features, wherein the multiple target features include operational behavior and at least one of the following: an object associated with the operational behavior, associated behavior of the object, and a time node corresponding to the associated behavior; acquiring evidence information associated with the multiple target features; and generating an attack evidence chain corresponding to the first alarm information based on the multiple target features, the correlation between the multiple target features, and the evidence information associated with the multiple target features, wherein the attack evidence chain includes attack evidence corresponding to each attack node in the attack chain corresponding to the first alarm information.

[0034] Based on the attack evidence chain generation method for business risk control provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides an attack evidence chain generation apparatus, electronic device, and computer-readable storage medium for business risk control.

[0035] This disclosure provides at least one embodiment of an attack evidence chain generation method for business risk control. By extracting target features from alarm information and determining the correlation between these features, suspicious points in the alarm information are identified. Based on these suspicious points, richer evidence information is further obtained. Then, by combining the suspicious points and the evidence information, the attack chain corresponding to the alarm information and the attack evidence of each attack node in the attack chain are determined, forming a complete and accurate attack evidence chain. For example, when the above method is applied to security protection systems such as cloud security protection products or security agents, it can improve the attack tracing capability of the security protection system, thereby enhancing the protection capability of the security protection system.

[0036] The embodiments and some examples of this disclosure will now be described in detail with reference to the accompanying drawings.

[0037] Figure 1 The illustration shows an application scenario of a security protection system provided by at least one embodiment of the present disclosure.

[0038] like Figure 1 As shown, the application scenario of this embodiment includes a security protection system 100. The embodiments of this disclosure do not limit the form of the security protection system 100. For example, the security protection system 100 can provide cloud security protection-related services in the form of a security AI agent. The security protection system 100 can be a cloud security platform, a cloud security plugin, a cloud security cloud service, etc.

[0039] In the embodiments of this disclosure, the security protection system 100 can perform alarm tracing. For example, the security protection system 100 can obtain alarm information 101, extract target features 102 from the alarm information 101, determine the correlation between target features 102, obtain evidence information 103 associated with target features 102, and thus form an attack evidence chain 104 corresponding to the alarm information 101.

[0040] In this way, the security protection system can collect richer and more comprehensive evidence information 103 related to alarm tracing based on the target features 102 in the alarm information 101 and the correlation between the target features 102, making the attack chain corresponding to the alarm information 101 more based and the evidence support stronger.

[0041] In some embodiments, the security protection system 100 can be connected to the artificial intelligence model 200 to perform alarm tracing. For example, the security protection system 100 can use the artificial intelligence model 200 to extract target features 102 and determine the correlation between target features 102. As another example, the security protection system 100 can also use the artificial intelligence model 200 to obtain evidence information associated with target features 102. Furthermore, the security protection system 100 can also use the artificial intelligence model 200 to generate an attack evidence chain 104 corresponding to alarm information 101.

[0042] In this way, by utilizing the artificial intelligence capabilities of the artificial intelligence model 200, an automated alarm tracing process can be achieved in the security protection system 100, eliminating the need for users (such as security operations personnel) to manually extract the attack evidence chain, thereby improving the efficiency of attack evidence chain generation in the security protection system 100.

[0043] This disclosure does not limit the form of the artificial intelligence model 200. For example, the artificial intelligence model 200 may include any one or a combination of multiple of the following: a large language model, a large visual model, a large audio model, and a multimodal large model. For example, the artificial intelligence model 200 may be a model built based on a transformer architecture, a model built based on a recurrent neural network, a model built based on an attention mechanism, etc. Alternatively, the artificial intelligence model 200 may also be a model obtained by improving upon the transformer architecture, such as a mixture of experts (MoE) model.

[0044] The embodiments disclosed herein do not limit the deployment method of the artificial intelligence model 200. For example, as Figure 1As shown, the artificial intelligence model 200 can be deployed outside the security protection system 100, meaning the security protection system 100 can perform alarm tracing by calling the external artificial intelligence model 200. Alternatively, the artificial intelligence model 200 can also be deployed inside the security protection system 100 as a functional module, assisting in alarm tracing during the operation of the security protection system 100.

[0045] It should be noted that, in this disclosure, the artificial intelligence model 200 (including the first artificial intelligence model, the second artificial intelligence model, and / or the third artificial intelligence model) can be obtained in various ways. For example, the artificial intelligence model 200 can be an existing, open-source general artificial intelligence model. Alternatively, the artificial intelligence model 200 can be an artificial intelligence model obtained by fine-tuning (e.g., full parameter fine-tuning or partial parameter fine-tuning) the historical security data of the security protection system 100 (e.g., historical alarm information, features of historical alarm information, historical attack evidence chains corresponding to historical alarm information, etc.) based on a pre-trained model.

[0046] The following will combine Figure 2 and Figure 3 The present disclosure provides a detailed description of at least one embodiment of an attack evidence chain generation method for business risk control.

[0047] Figure 2 The illustration shows a flowchart of an attack evidence chain generation method for business risk control provided in at least one embodiment of the present disclosure.

[0048] like Figure 2 As shown, the attack evidence chain generation method for business risk control in this embodiment includes steps S201 to S204. For example, the executing entity of this attack evidence chain generation method for business risk control can be an electronic device with a client deployed, an electronic device with a server deployed, or any electronic device that communicates between the client and the server; the embodiments of this disclosure do not limit this.

[0049] Step S201: Obtain the first alarm information.

[0050] The first alarm message can be understood as the alarm message detected and generated by the security protection system. The first alarm message can be associated with an alarm event. In other words, when the security protection system detects an alarm event, the first alarm message can be the alarm message associated with that alarm event. For example, if the security protection system is performing security protection on a virtual machine and detects an alarm event occurring on that virtual machine, it will then generate the first alarm message associated with that alarm event.

[0051] The first alarm information may include information from different dimensions related to the alarm event. For example, the first alarm information may include the alarm identifier, the time of occurrence of the alarm event, the alarm level, the alarm source, the alarm code, etc.

[0052] In some possible implementations, considering that the security protection system can detect and generate a large number of alarm messages, which may include erroneous alarm messages or alarm messages with low risk, after obtaining the first alarm message, the first alarm message can be preliminarily screened, and the alarm messages with higher risk can be retained as the final first alarm message.

[0053] For example, when the first alarm message includes an alarm level, first alarm messages with alarm levels indicating high risk are retained, while those indicating low risk are discarded. Another example is pre-configuring keywords for filtering alarm messages; matching these keywords with the first alarm message results in retaining the matching messages and discarding the unmatched ones. Yet another example is using a pre-trained risk assessment model to assess the risk of the first alarm message, retaining the first alarm message output by the risk assessment model.

[0054] In this way, the number of primary alarm messages that the security protection system needs to trace is reduced, the resource consumption of the security protection system is reduced, and erroneous alarm messages or low-risk alarm messages avoid consuming a large amount of computing resources.

[0055] Step S202: Extract multiple target features from the first alarm information and determine the correlation between the multiple target features.

[0056] In the embodiments of this disclosure, target features can be understood as suspicious points or include suspicious points; that is, target features can be suspicious features related to the first alarm information and the attack chain. Multiple target features may include operational behaviors and at least one of the following: objects associated with operational behaviors, time nodes corresponding to operational behaviors, associated behaviors of objects, and time nodes corresponding to associated behaviors.

[0057] Operational behavior can be understood as the action indicated by the target characteristic. For example, operational behavior could be object A sending a command to object B, object C communicating with object D, or object E logging into the system. An object can be understood as an entity appearing in the first alarm message. For example, an object could be an internet protocol (IP) address, a process, or a server. Objects associated with an operational behavior can be understood as objects involved in the target characteristic. For example, when the target characteristic is object A sending a command to object B, the objects associated with the operational behavior are object A and object B. Related behaviors of an object can be understood as other operational behaviors of the object in the first alarm message. A time node can be understood as the time node when the target characteristic appears. For example, when the target characteristic is an operational behavior, the time node corresponding to the operational behavior is the time node when the operational behavior appears; when the target characteristic is a related behavior of an object, the time node corresponding to the related behavior is the time node when the related behavior appears.

[0058] In other words, when extracting features from the first alarm information, not only is the operation behavior extracted, but also the object associated with the operation behavior, the time node corresponding to the operation behavior, the associated behavior of the object, and the time node corresponding to the associated behavior are extracted together. In this way, the types of target features are enriched, and comprehensive suspicious feature extraction is achieved.

[0059] The correlation between target features can be used to describe the relationship between target features. Target features with correlation can form suspicious point combinations. That is, by using correlation, independent suspicious features can be aggregated.

[0060] In some embodiments, determining the association between multiple target features may include at least one of the following: determining that multiple target features associated with the same object have an association relationship, or determining that multiple target features associated with the same time point have an association relationship.

[0061] For example, for a specific IP address, there is a correlation between the target characteristics of that IP address communicating by exploiting system vulnerabilities and the target characteristics of that IP address sending abnormal commands to high-privilege hosts. Similarly, for a specific time point, there is a correlation between the target characteristics of login behavior outside of working hours corresponding to that time point, the target characteristics of suspicious file downloads corresponding to that time point, and the target characteristics of abnormal communication during that time point.

[0062] In other words, the embodiments of this disclosure not only extract single suspicious features, but also construct the correlation between suspicious features, aggregate multiple suspicious features, ensure that key features in attack tracing are not missed, avoid the one-sidedness of a single suspicious feature, and achieve cross-dimensional correlation of suspicious features for complex first alarm information (such as the first alarm information of multi-path attacks).

[0063] In some possible implementations, artificial intelligence models can be used to extract target features and determine the relationships between target features. For example, a first model prompt message is generated, sent to a first artificial intelligence model, and the first artificial intelligence model returns multiple target features and the relationships between these features.

[0064] Considering that target features are usually in the form of natural language, the first artificial intelligence model can have natural language processing capabilities, be able to understand the meaning of natural language, and handle different types of natural language tasks. The first artificial intelligence model can also have multimodal information processing capabilities, be able to understand the meaning of multimodal information, and handle different types of multimodal tasks.

[0065] The first AI model can leverage prompt learning technology to extract target features and determine the relationships between them based on prompts provided by the first model. These prompts, also known as hints, are used in generative tasks (such as text generation, question answering, and dialogue tasks) to guide the AI ​​model to specific outputs. By configuring these prompts, the AI ​​model can understand the task's context and requirements, enabling it to handle different types of processing tasks without retraining, thus increasing its scalability and flexibility.

[0066] The first model prompt information may include: first alarm information, historical alarm analysis data related to the first alarm information, instruction information for indicating the extraction of target features from the first alarm information, and instruction information for indicating the determination of the correlation between target features.

[0067] Historical alarm analysis data related to the first alarm information can be understood as alarm analysis data generated by the security protection system within a historical time period, such as the correlation between historical target features. Historical alarm analysis data can be associated with the first alarm information; for example, the alarm information targeted by the historical alarm analysis data can have a similarity greater than a similarity threshold with the first alarm information.

[0068] For example, the instruction information used to indicate the extraction of target features from the first alarm information can be: the instruction information used to indicate the extraction of target features from the first alarm information based on historical alarm analysis data related to the first alarm information; the instruction information used to indicate the determination of the correlation between target features can be: the instruction information used to indicate the determination of the correlation between target features based on historical alarm analysis data related to the first alarm information.

[0069] By sending the first model's prompt information to the first artificial intelligence model, and leveraging the prompting capabilities of the first model's prompt information, the first artificial intelligence model can combine historical alarm analysis data to analyze the first alarm information, extract target features from the first alarm information, and determine the correlation between target features, thereby achieving automatic extraction and automatic association of suspicious features.

[0070] Step S203: Obtain evidence information associated with multiple target features.

[0071] Evidence information can be understood as attack evidence used to corroborate the attack chain. In other words, by using evidence information, the attack chain corresponding to the first alarm information can be determined, and alarm source tracing can be achieved for the first alarm information.

[0072] In some embodiments, an acquisition instruction may be determined first, and evidence information associated with multiple target features may be acquired by executing the acquisition instruction.

[0073] The process of obtaining evidence information is explained below.

[0074] Figure 3 The illustration shows a flowchart of a method for obtaining evidence information provided in at least one embodiment of the present disclosure.

[0075] like Figure 3 As shown, the method for obtaining evidence information may include steps S301 to S303.

[0076] Step S301: Generate the second model prompt information.

[0077] Step S302: Send the second model prompt information to the second artificial intelligence model, and receive the first acquisition instruction of the first target feature returned by the second artificial intelligence model.

[0078] Step S303: According to the first acquisition instruction, acquire evidence information associated with the first target feature.

[0079] In some possible implementations, a second artificial intelligence model is used to determine a first acquisition instruction for a first target feature. The first target feature can be any one of multiple target features, and the first acquisition instruction can be understood as an investigation instruction for collecting evidence information.

[0080] Similar to the first artificial intelligence model, the second artificial intelligence model can have natural language processing capabilities, be able to understand the meaning of natural language, and handle different types of natural language tasks. The second artificial intelligence model can also have multimodal information processing capabilities, be able to understand the meaning of multimodal information, and handle different types of multimodal tasks. The second artificial intelligence model can also generate the first acquisition instruction based on the prompting information of the second model, using prompting learning technology.

[0081] It should be noted that in some embodiments, the second artificial intelligence model may be the same as the first artificial intelligence model, or in other embodiments, it may be a different model from the first artificial intelligence model.

[0082] The second model prompt information may include: a first target feature, other target features that are related to the first target feature, and instruction information for indicating the acquisition of evidence information related to the first target feature.

[0083] For each target feature, by sending the second model's prompt information to the second artificial intelligence model, the second artificial intelligence model can analyze the target feature with the help of the prompt information and generate acquisition instructions for collecting more relevant information about the target feature, thereby realizing the automatic advancement of obtaining evidence information.

[0084] In some embodiments, for objects whose first target feature is not associated with an operational behavior, the role of the first target feature in the attack chain can also be marked according to the association relationship between the first target feature and other target features.

[0085] In other words, for a given object, its role in the attack process is determined by the correlation between its characteristics and other characteristics. For example, for a given IP address, other characteristics associated with that target feature include the IP address's ability to communicate using system vulnerabilities and the IP address's ability to send abnormal commands to high-privilege hosts. Thus, the role of that IP address in the attack chain is labeled as a "command and control server".

[0086] The embodiments of this disclosure do not limit the above-described method of role labeling. For example, a mapping relationship between target features and roles can be pre-constructed. Based on the first target feature and its association with other target features, the role of the first target feature in the attack chain can be labeled according to this mapping relationship. Another example is the use of a pre-trained role labeling model to label the first target feature. The role labeling model analyzes the first target feature and other associated target features, and outputs the role of the first target feature in the attack chain.

[0087] By assigning roles to the first target feature belonging to the object, the second model prompt information may further include: an instruction to acquire historical features that have the same role as the first target feature in the attack chain. In this case, the instruction in the second model prompt information for indicating the acquisition of evidence information associated with the first target feature can be: an instruction for generating a first acquisition instruction based on the acquisition instruction of historical features that have the same role as the first target feature in the attack chain.

[0088] Thus, by using role labeling, during the process of obtaining evidence information, the first acquisition instruction of the first target feature is generated by referring to the acquisition instructions of the historical characteristics of the same role. This makes the generation of the first acquisition instruction based on evidence and more closely aligned with the role of the first target feature in the attack chain.

[0089] In other embodiments, risk level information of multiple target features can also be obtained, which can be used to indicate the risk level of the target features. For example, the risk level information can be high risk and low risk.

[0090] For a first target feature with different risk levels, different methods can be used to obtain evidence information. The second model prompt information, which indicates the acquisition of evidence information associated with the first target feature, includes information indicating the execution of the following steps: in response to the risk level information of the first target feature satisfying a first condition, acquire evidence information associated with the first target feature; or in response to the risk level information of the first target feature satisfying a second condition, acquire auxiliary information of the first target feature, and in response to the auxiliary information satisfying a third condition, acquire evidence information associated with the first target feature.

[0091] The first condition can be used to indicate that the risk level of the target feature is relatively high, and the second condition can be used to indicate that the risk level of the target feature is relatively low. For example, the first condition can be that the risk level information is high risk, and the second condition can be that the risk registration information is low risk.

[0092] In other words, in the embodiments of this disclosure, for a high-risk first target feature, evidence information associated with the first target feature is directly obtained; for a low-risk first target feature, auxiliary information of the first target feature is first obtained; when the auxiliary information meets a third condition (e.g., the condition that the first target feature is abnormal), evidence information associated with the first target feature is then obtained.

[0093] In this way, by classifying target features according to different risk levels, the investigation instructions are matched with the risk levels of the target features, increasing the accuracy of the investigation instructions. For example, for a first target feature whose risk level information meets the first condition, the first acquisition instruction could be "conduct sandbox analysis, focusing on detecting persistent operations, data detection behaviors, and malicious code variant characteristics." For a first target feature whose risk level meets the second condition, the first acquisition instruction could be "query basic attribute information such as geographical location; if the basic attribute information is abnormal (i.e., meets the third condition), then conduct a deep threat intelligence retrieval."

[0094] After the second artificial intelligence model outputs the first acquisition command, the first acquisition command can be executed by calling a security tool to obtain evidence information of the first target feature.

[0095] Security tools can be understood as tools that connect to a security protection system. Security tools can provide functions related to cloud security protection, which can be called by the security protection system during actual operation.

[0096] Since the first acquisition instruction can be related to data collection and determination of intermediate results, at least one security tool is determined, at least one security tool is invoked, and evidence information related to the first target feature is received from at least one security tool.

[0097] In other words, based on the capabilities of the third-party security tools integrated into the security protection system, at least one security tool capable of executing the first acquisition instruction is determined. For example, the security protection system's database may store the strengths of each security tool in various scenarios; for instance, security tool A excels at quickly querying IP addresses, security tool B excels at deeply mining historical attack events of IP addresses, security tool C is suitable for real-time initial screening, and security tool D is suitable for in-depth behavioral analysis. Thus, the first acquisition instruction is matched with the security tools to determine at least one security tool for executing the first acquisition instruction, and then at least one security tool is invoked to acquire evidence information.

[0098] The embodiments of this disclosure do not limit the methods for determining security tools described above. For example, a mapping relationship between acquisition instructions and security tools can be pre-built, and at least one security tool can be determined based on the mapping relationship according to the first acquisition instruction. Another example is using a pre-trained tool determination model to analyze the first acquisition instruction; the tool determination model combines the tool capabilities of each security tool to output at least one security tool.

[0099] Furthermore, in at least one embodiment of this disclosure, the supplementation of security tools is also supported. At least one security tool may include a second security tool, the second security tool is invoked, in response to the failure of the second security tool invocation, a set of security tools is determined, at least one security tool in the set of security tools is invoked, and evidence information related to the first target feature returned by at least one security tool is received.

[0100] At least one security tool in the security tool set is used to perform the same function as the second security tool.

[0101] In other words, when there is a problem in calling the second security tool, a set of security tools that can achieve the same capabilities as the second security tool are selected to replace it. By calling the security tools in this set of security tools, the purpose of obtaining evidence information related to the first target feature can still be achieved even if the second security tool fails to be called.

[0102] For example, if the second security tool is a sandbox analysis tool, and the invocation of the second security tool fails (e.g., the sandbox analysis did not yield results), the security tool set can include static decompilation tools and behavioral simulation tools. By invoking the security tools in the security tool set, the attack tracing process can be advanced, avoiding the impact of security tool invocation failure on the efficiency of attack tracing.

[0103] Furthermore, in at least one embodiment of this disclosure, dynamic adjustment of the acquisition instruction is also supported. At least one security tool may include a first security tool, which is used to acquire evidence information of a first dimension. After receiving evidence information associated with a first target feature returned by at least one security tool, in response to the first security tool returning empty evidence information associated with the first target feature, a third model prompt message is generated, the third model prompt message is sent to a second artificial intelligence model, a second acquisition instruction for the first target feature is received from the second artificial intelligence model, and evidence information associated with the first target feature is acquired according to the second acquisition instruction.

[0104] The third model prompt information may include: a first target feature, other target features that are related to the first target feature, and instruction information for indicating the acquisition of evidence information that is related to the first target feature but is not in the first dimension.

[0105] By sending the third model's prompts to the second AI model, and leveraging the prompting capabilities of the third model's prompts, the second AI model can generate acquisition instructions from dimensions different from the first dimension. In other words, if the evidence information returned by the first security tool does not yield the desired result, the second AI model generates a progressive acquisition instruction (i.e., a second acquisition instruction). By executing the second acquisition instruction, further evidence information from other dimensions associated with the first target feature is obtained. This multi-dimensional acquisition of evidence information associated with the first target feature avoids interruptions in the evidence investigation due to invalid results from a single dimension.

[0106] For example, when the evidence information returned by the first security tool related to the first target feature is "the IP address has no clear label in the threat intelligence database", the second artificial intelligence model can further generate a second acquisition instruction, such as supplementing the query of the historical communication domain name and associated malicious sample hash of the IP address, and using the second acquisition instruction to collect evidence information from different dimensions.

[0107] Step S204: Generate an attack evidence chain corresponding to the first alarm information based on multiple target features, the correlation between multiple target features, and evidence information associated with multiple target features.

[0108] After obtaining evidence information associated with multiple target features, existing information (i.e., multiple target features, the relationships between multiple target features, and evidence information associated with multiple target features) can be integrated to perform attack tracing and generate an attack evidence chain corresponding to the first alarm information. This attack evidence chain may include attack evidence corresponding to each attack node in the attack chain corresponding to the first alarm information.

[0109] In other words, the attack chain corresponding to the first alarm message includes multiple attack nodes, and each attack node is associated with corresponding attack evidence, which is used to verify the logical correctness of the attack chain.

[0110] In some possible implementations, a third artificial intelligence model is used to generate an attack evidence chain corresponding to the first alarm message. A fourth model prompt message is generated and sent to the third artificial intelligence model, which then returns the attack evidence chain of the first alarm message.

[0111] Similar to the first AI model, the third AI model can have natural language processing capabilities, understand the meaning of natural language, and handle different types of natural language tasks. The third AI model can also have multimodal information processing capabilities, understand the meaning of multimodal information, and handle different types of multimodal tasks. The third AI model can also generate attack evidence chains based on prompting learning technology and prompting information from the fourth model.

[0112] It should be noted that in some embodiments, the third artificial intelligence model may be the same model as the first artificial intelligence model, or in other embodiments, it may be a different model from the first artificial intelligence model.

[0113] The fourth model prompt information may include: multiple target features, the correlation between multiple target features, evidence information associated with multiple target features, indication information for indicating the attack chain corresponding to the first alarm information based on the time sequence of multiple target features, and indication information for indicating the association of evidence information associated with multiple target features with each attack node in the attack chain corresponding to the first alarm information.

[0114] By sending the prompts from the fourth model to the third AI model, and leveraging the prompting capabilities of the fourth model, the third AI model can use the acquired evidence as attack evidence in a chronological and causal manner. It can then use the characteristics of each target to identify the attack nodes in the attack chain, forming a complete chain of attack evidence supported by evidence.

[0115] For example, the target characteristics, in chronological order, include the first communication via IP address, downloading a file via that IP address, executing the file, and transmitting data to an external domain. Combined with the evidence information associated with the above target characteristics, an attack chain is formed, including an "initial intrusion" attack node, a "malicious code execution" attack node, a "persistent" attack node, and a "data leakage" attack node. Furthermore, each attack node is associated with corresponding evidence information to support its claims.

[0116] In some embodiments, each attack node may also be labeled with the strength of its evidence support. For example, the strength of the evidence support for each attack node may be labeled based on the quantity and credibility of the evidence information associated with it, and this strength of evidence support can be used as a reference in subsequent alarm handling.

[0117] Furthermore, in at least one embodiment of this disclosure, a logic vulnerability self-checking mechanism is also embedded. The verification result of the attack evidence chain is determined, indicating whether the attack evidence chain contains contradictions or breaks. In response to the verification result indicating that the attack evidence chain contains contradictions or breaks, evidence information associated with multiple target features is acquired again. Based on the re-acquired evidence information associated with multiple target features, the attack evidence chain of the first alarm information is updated.

[0118] In other words, for the generated chain of attack evidence, it is verified whether there are contradictions or breaks in the chain of attack evidence. If there are contradictions or breaks, it indicates that the obtained evidence information is not comprehensive enough. A supplementary investigation instruction is generated to obtain evidence information again, further enrich the evidence information, and update the chain of attack evidence until a closed-loop chain of attack evidence without logical breaks or contradictions is formed.

[0119] For example, if the timestamp of a certain action in the attack evidence chain conflicts with the attack sequence, it indicates that there is a contradiction in the attack evidence chain. If there is a lack of corresponding evidence information between the attack node "lateral movement" and the attack node "data leakage", it indicates that there is a break in the attack evidence chain. In this case, the evidence information can be retrieved again to correct the logical vulnerabilities in the attack evidence chain.

[0120] The embodiments disclosed herein do not limit the methods for verifying the chain of evidence of an attack. For example, an artificial intelligence model can be used to analyze the chain of evidence of an attack, and the analytical capabilities of the artificial intelligence model can be used to determine whether there are contradictions or breaks in the chain of evidence of an attack.

[0121] The method for generating attack evidence chains provided in this disclosure significantly improves the efficiency of generating attack evidence chains corresponding to alarm information, ensures the standardization of the process of target feature extraction, evidence information acquisition and attack evidence chain generation, and thus enhances the alarm analysis capabilities of the security protection system.

[0122] Based on the attack evidence chain generation method for business risk control provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides an attack evidence chain generation apparatus for business risk control. The following will be combined with... Figure 4 This attack evidence chain generation device used for business risk control is described in detail.

[0123] Figure 4 The illustration shows a schematic diagram of an attack evidence chain generation device for business risk control provided in at least one embodiment of the present disclosure.

[0124] like Figure 4 As shown, the attack evidence chain generation device 400 for business risk control in this embodiment includes a first acquisition module 401, a processing module 402, a second acquisition module 403, and a generation module 404. For example, these units or modules can be implemented by hardware (e.g., circuit) modules or software modules, as is the case in the following embodiments, and will not be repeated here. For example, these units or modules can be implemented by a central processing unit (CPU), a general-purpose graphics processor (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, along with corresponding computer instructions.

[0125] The first acquisition module 401 is configured to acquire first alarm information. For example, the first acquisition module 401 can be configured to execute step S201 described above. The specific implementation principle can be referred to the relevant description of step S201, which will not be repeated here.

[0126] The processing module 402 is configured to: extract multiple target features from the first alarm information, and determine the correlation between the multiple target features, wherein the multiple target features include an operation behavior and at least one of the following: an object associated with the operation behavior, a time node corresponding to the operation behavior, an associated behavior of the object, and a time node corresponding to the associated behavior. For example, the processing module 402 can be configured to execute step S202 described above; its specific implementation principle can be found in the relevant description of step S202, and will not be repeated here.

[0127] The second acquisition module 403 is configured to acquire evidence information associated with the plurality of target features. For example, the second acquisition module 403 can be configured to execute step S203 as described above; its specific implementation principle can be found in the relevant description of step S203, and will not be repeated here.

[0128] The generation module 404 is configured to generate an attack evidence chain corresponding to the first alarm information based on the plurality of target features, the correlation between the plurality of target features, and the evidence information associated with the plurality of target features. The attack evidence chain includes attack evidence corresponding to each attack node in the attack chain corresponding to the first alarm information. For example, the generation module 404 can be configured to execute step S204 described above. The specific implementation principle can be found in the relevant description of step S204, and will not be repeated here.

[0129] In at least one embodiment of this disclosure, the processing module 402 is further configured to: determine that there is an association relationship between multiple target features associated with the same object; determine that there is an association relationship between multiple target features associated with the same time node.

[0130] In at least one embodiment of this disclosure, the processing module 402 is further configured to: generate first model prompt information, wherein the first model prompt information includes: first alarm information, historical alarm analysis data related to the first alarm information, indication information for indicating the extraction of target features from the first alarm information, and indication information for indicating the determination of the correlation between the target features; send the first model prompt information to a first artificial intelligence model, and receive the plurality of target features and the correlation between the plurality of target features returned by the first artificial intelligence model.

[0131] In at least one embodiment of this disclosure, the second acquisition module 403 is further configured to: generate second model prompt information, wherein the second model prompt information includes: a first target feature, other target features associated with the first target feature, and indication information for indicating the acquisition of evidence information associated with the first target feature, wherein the first target feature is any one of the plurality of target features; send the second model prompt information to a second artificial intelligence model, receive a first acquisition instruction for the first target feature returned by the second artificial intelligence model; and acquire evidence information associated with the first target feature according to the first acquisition instruction.

[0132] In at least one embodiment of this disclosure, the first target feature is an object associated with the operation behavior, and the attack evidence chain generation device 400 may further include an annotation module, which is configured to: annotate the role of the first target feature in the attack chain according to the association relationship between the first target feature and other target features; wherein, the second model prompt information further includes: an instruction to obtain historical features that are the same as the role of the first target feature in the attack chain.

[0133] In at least one embodiment of this disclosure, the second acquisition module 403 is further configured to: acquire risk level information of the plurality of target features; the indication information in the second model prompt information for indicating the acquisition of evidence information associated with the first target feature includes information for indicating the execution of the following steps: in response to the risk level information of the first target feature satisfying a first condition, acquire evidence information associated with the first target feature; or in response to the risk level information of the first target feature satisfying a second condition, acquire auxiliary information of the first target feature, and in response to the auxiliary information satisfying a third condition, acquire evidence information associated with the first target feature.

[0134] In at least one embodiment of this disclosure, the second acquisition module 403 is further configured to: determine at least one security tool according to the first acquisition instruction; invoke the at least one security tool; and receive evidence information related to the first target feature returned by the at least one security tool.

[0135] In at least one embodiment of this disclosure, the at least one security tool includes a first security tool for acquiring evidence information of a first dimension; the second acquisition module 403 is further configured to: generate third model prompt information in response to the first security tool returning empty evidence information associated with the first target feature, wherein the third model prompt information includes: the first target feature, other target features associated with the first target feature, and indication information for indicating the acquisition of evidence information associated with the first target feature but not of the first dimension; send the third model prompt information to the second artificial intelligence model, receive a second acquisition instruction for the first target feature returned by the second artificial intelligence model; and acquire evidence information associated with the first target feature according to the second acquisition instruction.

[0136] In at least one embodiment of this disclosure, the at least one security tool includes a second security tool, and the second acquisition module 403 is further configured to: invoke the second security tool; in response to the failure of the invocation of the second security tool, determine a set of security tools, wherein at least one security tool in the set of security tools is used to perform the same function as the second security tool; invoke the at least one security tool in the set of security tools, and receive evidence information associated with the first target feature returned by the at least one security tool.

[0137] In at least one embodiment of this disclosure, the generation module 404 is further configured to: generate fourth model prompt information, wherein the fourth model prompt information includes: the plurality of target features, the correlation between the plurality of target features, the evidence information associated with the plurality of target features, the indication information for indicating that the attack chain corresponding to the first alarm information is generated based on the time sequence of the plurality of target features, and the indication information for indicating that the evidence information associated with the plurality of target features is associated with each attack node in the attack chain corresponding to the first alarm information; send the fourth model prompt information to a third artificial intelligence model, and receive the attack evidence chain of the first alarm information returned by the third artificial intelligence model.

[0138] In at least one embodiment of this disclosure, the attack evidence chain generation device 400 for business risk control may further include a verification module, which is configured to: determine the verification result of the attack evidence chain, wherein the verification result indicates whether the attack evidence chain has contradictions or breaks; in response to the verification result indicating that the attack evidence chain has contradictions or breaks, re-acquire evidence information associated with the plurality of target features; and update the attack evidence chain of the first alarm information based on the re-acquired evidence information associated with the plurality of target features.

[0139] It should be noted that, for clarity and brevity, this disclosure does not provide all the constituent units of the attack evidence chain generation device 400 for business risk control. To achieve the necessary functions of this device, those skilled in the art can provide and configure other constituent units (not shown) according to specific needs, and this disclosure does not impose any limitations on this.

[0140] At least one embodiment of this disclosure also provides an electronic device, including: a processing device; a storage device including one or more computer program modules; wherein the one or more computer program modules are stored in the storage device and configured to be executed by the processing device, and the one or more computer program modules are used to implement the attack evidence chain generation method for business risk control provided in any embodiment of this disclosure.

[0141] For example, the processing device may be a central processing unit (CPU), digital signal processor (DSP), image processor (GPU), general-purpose graphics processor (GPGPU), or other form of processing unit with data processing capabilities and / or instruction execution capabilities. It may be a general-purpose processor or a dedicated processor and may control other components in the electronic device to perform the desired functions.

[0142] For example, the storage device may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and a processing device may execute these program instructions to implement the functions (implemented by the processing device) in the embodiments of this disclosure and / or other desired functions. Various application programs and various data may also be stored in the computer-readable storage medium, which is not limited in the embodiments of this disclosure.

[0143] The following is for reference. Figure 5 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 500 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0144] like Figure 5 As shown, the electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the electronic device 500. The processing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0145] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0146] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a ROM 502. When the computer program is executed by the processing device 501, it performs the functions defined in the methods of embodiments of this disclosure.

[0147] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0148] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0149] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0150] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: acquire first alarm information; extract multiple target features from the first alarm information and determine the correlation between the multiple target features; acquire evidence information associated with the multiple target features; and generate an attack evidence chain corresponding to the first alarm information based on the multiple target features, the correlation between the multiple target features, and the evidence information associated with the multiple target features.

[0151] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0152] Embodiments of this disclosure also provide a computer program product comprising one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the processes or functions described in any embodiment of this disclosure are generated.

[0153] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0154] When the computer program product is executed by a computer, the computer performs any of the aforementioned methods. The computer program product can be a software installation package; when any of the aforementioned methods is required, the computer program product can be downloaded and executed on the computer.

[0155] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0156] The units or modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units or modules do not necessarily constitute a limitation on the unit or module itself.

[0157] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0158] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0159] According to one or more embodiments of this disclosure, Example 1 provides a method for generating an attack evidence chain for business risk control, including:

[0160] Obtain the first alarm information;

[0161] Multiple target features are extracted from the first alarm information, and the correlation between the multiple target features is determined. The multiple target features include operation behavior and at least one of the following: an object associated with the operation behavior, a time node corresponding to the operation behavior, an associated behavior of the object, and a time node corresponding to the associated behavior.

[0162] Obtain evidence information associated with the multiple target features;

[0163] Based on the multiple target features, the correlation between the multiple target features, and the evidence information associated with the multiple target features, an attack evidence chain corresponding to the first alarm information is generated, wherein the attack evidence chain includes: attack evidence corresponding to each attack node in the attack chain corresponding to the first alarm information.

[0164] According to one or more embodiments of this disclosure, Example 2 provides the method for determining the association between the plurality of target features as in Example 1, including at least one of the following:

[0165] It determines that multiple target features associated with the same object have a relationship;

[0166] It is determined that there is a correlation between multiple target features associated with the same time point.

[0167] According to one or more embodiments of this disclosure, Example 3 provides the extraction of multiple target features from the first alarm information as in Example 2, and the determination of the correlation between the multiple target features, including:

[0168] Generate first model prompt information, wherein the first model prompt information includes: first alarm information, historical alarm analysis data related to the first alarm information, indication information for indicating the extraction of target features from the first alarm information, and indication information for indicating the determination of the correlation between the target features;

[0169] The first model prompt information is sent to the first artificial intelligence model, and the multiple target features and the correlation between the multiple target features are returned by the first artificial intelligence model.

[0170] According to one or more embodiments of this disclosure, Example 4 provides the acquisition of evidence information associated with the plurality of target features as in Example 1, including:

[0171] Generate second model prompt information, wherein the second model prompt information includes: a first target feature, other target features that are related to the first target feature, and indication information for indicating the acquisition of evidence information related to the first target feature, wherein the first target feature is any one of the plurality of target features;

[0172] Send the second model prompt information to the second artificial intelligence model, and receive the first acquisition instruction of the first target feature returned by the second artificial intelligence model;

[0173] According to the first acquisition instruction, acquire evidence information associated with the first target feature.

[0174] According to one or more embodiments of this disclosure, Example 5 provides an object in Example 4 whose first target feature is associated with the operational behavior, and further includes:

[0175] Based on the correlation between the first target feature and other target features, the role of the first target feature in the attack chain is marked;

[0176] The second model prompt information also includes: instructions for obtaining historical features that play the same role in the attack chain as the first target feature.

[0177] According to one or more embodiments of this disclosure, Example Six provides the method of Example Four, further comprising:

[0178] Obtain risk level information for the multiple target features;

[0179] The instruction information in the second model prompt information for indicating the acquisition of evidence information associated with the first target feature includes information for indicating the execution of the following steps:

[0180] In response to the risk level information of the first target feature satisfying a first condition, evidence information associated with the first target feature is obtained; or

[0181] In response to the risk level information of the first target feature satisfying a second condition, auxiliary information of the first target feature is obtained, and in response to the auxiliary information satisfying a third condition, evidence information associated with the first target feature is obtained.

[0182] According to one or more embodiments of this disclosure, Example 7 provides the method of obtaining evidence information associated with the first target feature according to the acquisition instruction in Example 4, including:

[0183] Based on the first acquisition instruction, at least one security tool is determined;

[0184] Invoke the at least one security tool and receive evidence information returned by the at least one security tool that is associated with the first target feature.

[0185] According to one or more embodiments of this disclosure, Example 8 provides at least one security tool from Example 7, including a first security tool, the first security tool being used to obtain evidence information in a first dimension;

[0186] After receiving the evidence information associated with the first target feature returned by the at least one security tool, the method further includes:

[0187] In response to the first security tool returning empty evidence information associated with the first target feature, a third model prompt is generated, wherein the third model prompt includes: the first target feature, other target features associated with the first target feature, and indication information for indicating the acquisition of evidence information associated with the first target feature but not the first dimension;

[0188] The third model prompt information is sent to the second artificial intelligence model, and the second acquisition instruction of the first target feature returned by the second artificial intelligence model is received;

[0189] According to the second acquisition instruction, acquire evidence information associated with the first target feature.

[0190] According to one or more embodiments of this disclosure, Example 9 provides at least one security tool from Example 7 that includes a second security tool;

[0191] The invocation of the at least one security tool and the receipt of evidence information returned by the at least one security tool that is associated with the first target feature include:

[0192] Invoke the second security tool;

[0193] In response to the failure of the second security tool invocation, a set of security tools is determined, wherein at least one security tool in the set of security tools is used to perform the same function as the second security tool;

[0194] Invoke at least one security tool from the security tool set, and receive evidence information related to the first target feature returned by the at least one security tool.

[0195] According to one or more embodiments of this disclosure, Example 10 provides the generation of an attack evidence chain corresponding to the first alarm information based on the plurality of target features, the correlation between the plurality of target features, and the evidence information associated with the plurality of target features, including:

[0196] Generate fourth model prompt information, wherein the fourth model prompt information includes: the plurality of target features, the correlation between the plurality of target features, the evidence information associated with the plurality of target features, the indication information for indicating that the attack chain corresponding to the first alarm information is generated based on the time sequence of the plurality of target features, and the indication information for indicating that the evidence information associated with the plurality of target features is associated with each attack node in the attack chain corresponding to the first alarm information.

[0197] The fourth model prompt information is sent to the third artificial intelligence model, and the attack evidence chain of the first alarm information returned by the third artificial intelligence model is received.

[0198] According to one or more embodiments of this disclosure, Example 11 provides a method from any of Examples 1 to 10, further comprising:

[0199] Determine the verification result of the attack evidence chain, wherein the verification result characterizes whether there is a contradiction or a break in the attack evidence chain;

[0200] In response to the verification result indicating that the attack evidence chain has contradictions or breaks, the process of obtaining evidence information associated with the multiple target features is repeated.

[0201] The attack evidence chain of the first alarm information is updated based on the evidence information associated with the multiple target features that are acquired again.

[0202] According to one or more embodiments of this disclosure, Example Twelve provides an attack evidence chain generation apparatus for business risk control, comprising:

[0203] The first acquisition module is configured to acquire the first alarm information.

[0204] The processing module is configured to: extract multiple target features from the first alarm information, and determine the association relationship between the multiple target features, wherein the multiple target features include operation behavior and at least one of the following: an object associated with the operation behavior, a time node corresponding to the operation behavior, an associated behavior of the object, and a time node corresponding to the associated behavior;

[0205] The second acquisition module is configured to: acquire evidence information associated with the plurality of target features;

[0206] The generation module is configured to generate an attack evidence chain corresponding to the first alarm information based on the plurality of target features, the correlation between the plurality of target features, and the evidence information associated with the plurality of target features, wherein the attack evidence chain includes attack evidence corresponding to each attack node in the attack chain corresponding to the first alarm information.

[0207] According to one or more embodiments of this disclosure, Example Thirteen provides an electronic device, including:

[0208] Processing device; and

[0209] Storage device, including one or more computer program instructions;

[0210] The one or more computer program instructions are executed by the processing device to perform the attack evidence chain generation method for business risk control provided in at least one embodiment of the present disclosure.

[0211] According to one or more embodiments of the present disclosure, Example Fourteen provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the attack evidence chain generation method for business risk control provided in at least one embodiment of the present disclosure.

[0212] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0213] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0214] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A method for generating an attack evidence chain for business risk control, comprising: Obtain the first alarm information; Multiple target features are extracted from the first alarm information, and the correlation between the multiple target features is determined. The multiple target features include operation behavior, object associated with the operation behavior, time node corresponding to the operation behavior, associated behavior of the object, and time node corresponding to the associated behavior. Obtain evidence information associated with the plurality of target features, wherein the evidence information associated with the plurality of target features is used to generate attack evidence in the attack evidence chain; Based on the multiple target features, the correlation between the multiple target features, and the evidence information associated with the multiple target features, an attack evidence chain corresponding to the first alarm information is generated. The attack evidence chain includes: the attack link corresponding to the first alarm information, and each attack node in the attack link is associated with corresponding attack evidence.

2. The method according to claim 1, wherein, Determining the association between the plurality of target features includes at least one of the following: It determines that multiple target features associated with the same object have a relationship; It is determined that there is a correlation between multiple target features associated with the same time point.

3. The method according to claim 1, wherein, The step of extracting multiple target features from the first alarm information and determining the correlation between the multiple target features includes: Generate first model prompt information, wherein the first model prompt information includes: first alarm information, historical alarm analysis data related to the first alarm information, indication information for indicating the extraction of target features from the first alarm information, and indication information for indicating the determination of the correlation between the target features; The first model prompt information is sent to the first artificial intelligence model, and the multiple target features and the correlation between the multiple target features are returned by the first artificial intelligence model.

4. The method according to claim 1, wherein, The acquisition of evidence information associated with the plurality of target features includes: Generate second model prompt information, wherein the second model prompt information includes: a first target feature, other target features that are related to the first target feature, and indication information for indicating the acquisition of evidence information related to the first target feature, wherein the first target feature is any one of the plurality of target features; Send the second model prompt information to the second artificial intelligence model, and receive the first acquisition instruction of the first target feature returned by the second artificial intelligence model; According to the first acquisition instruction, acquire evidence information associated with the first target feature.

5. The method according to claim 4, wherein, The first target feature is an object associated with the operation behavior, and the method further includes: Based on the correlation between the first target feature and other target features, the role of the first target feature in the attack chain is marked; The second model prompt information also includes: instructions for obtaining historical features that play the same role in the attack chain as the first target feature.

6. The method according to claim 4, further comprising: Obtain risk level information for the multiple target features; The instruction information in the second model prompt information for indicating the acquisition of evidence information associated with the first target feature includes information for indicating the execution of the following steps: In response to the risk level information of the first target feature satisfying a first condition, evidence information associated with the first target feature is obtained; or In response to the risk level information of the first target feature satisfying a second condition, auxiliary information of the first target feature is obtained, and in response to the auxiliary information satisfying a third condition, evidence information associated with the first target feature is obtained.

7. The method according to claim 4, wherein, The step of acquiring evidence information associated with the first target feature according to the acquisition instruction includes: Based on the first acquisition instruction, at least one security tool is determined; Invoke the at least one security tool and receive evidence information returned by the at least one security tool that is associated with the first target feature.

8. The method according to claim 7, wherein, The at least one security tool includes a first security tool, which is used to obtain evidence information in a first dimension; After receiving the evidence information associated with the first target feature returned by the at least one security tool, the method further includes: In response to the first security tool returning empty evidence information associated with the first target feature, a third model prompt is generated, wherein the third model prompt includes: the first target feature, other target features associated with the first target feature, and indication information for indicating the acquisition of evidence information associated with the first target feature but not the first dimension; The third model prompt information is sent to the second artificial intelligence model, and the second acquisition instruction of the first target feature returned by the second artificial intelligence model is received; According to the second acquisition instruction, acquire evidence information associated with the first target feature.

9. The method according to claim 7, wherein, The at least one security tool includes a second security tool; The invocation of the at least one security tool and the receipt of evidence information returned by the at least one security tool that is associated with the first target feature include: Invoke the second security tool; In response to the failure of the second security tool invocation, a set of security tools is determined, wherein at least one security tool in the set of security tools is used to perform the same function as the second security tool; Invoke at least one security tool from the security tool set, and receive evidence information related to the first target feature returned by the at least one security tool.

10. The method according to claim 1, wherein, The step of generating an attack evidence chain corresponding to the first alarm information based on the multiple target features, the correlation between the multiple target features, and the evidence information associated with the multiple target features includes: Generate fourth model prompt information, wherein the fourth model prompt information includes: the plurality of target features, the correlation between the plurality of target features, the evidence information associated with the plurality of target features, the indication information for indicating that the attack chain corresponding to the first alarm information is generated based on the time sequence of the plurality of target features, and the indication information for indicating that the evidence information associated with the plurality of target features is associated with each attack node in the attack chain corresponding to the first alarm information. The fourth model prompt information is sent to the third artificial intelligence model, and the attack evidence chain of the first alarm information returned by the third artificial intelligence model is received.

11. The method according to any one of claims 1 to 10, further comprising: Determine the verification result of the attack evidence chain, wherein the verification result characterizes whether there is a contradiction or a break in the attack evidence chain; In response to the verification result indicating that the attack evidence chain has contradictions or breaks, the process of obtaining evidence information associated with the multiple target features is repeated. The attack evidence chain of the first alarm information is updated based on the evidence information associated with the multiple target features that are acquired again.

12. An attack evidence chain generation device for business risk control, comprising: The first acquisition module is configured to acquire the first alarm information. The processing module is configured to: extract multiple target features from the first alarm information, and determine the correlation between the multiple target features, wherein the multiple target features include operation behavior, objects associated with the operation behavior, time nodes corresponding to the operation behavior, associated behaviors of the objects, and time nodes corresponding to the associated behaviors; The second acquisition module is configured to: acquire evidence information associated with the plurality of target features, wherein the evidence information associated with the plurality of target features is used to generate attack evidence in the attack evidence chain; The generation module is configured to generate an attack evidence chain corresponding to the first alarm information based on the plurality of target features, the correlation between the plurality of target features, and the evidence information associated with the plurality of target features. The attack evidence chain includes an attack link corresponding to the first alarm information, wherein each attack node in the attack link is associated with corresponding attack evidence.

13. An electronic device, comprising: Processing device; as well as Storage device, including one or more computer program instructions; The one or more computer program instructions are executed by the processing device according to any one of claims 1 to 11.

14. A computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, The method of any one of claims 1 to 11 is implemented when the computer-readable instructions are executed by a processor.

Citation Information

Patent Citations

  • Attack chain topology construction method and device

    CN112738071A

  • Information analysis method and device and computer readable storage medium

    CN114826685A