Threat hunting method and device, computer storage medium and terminal

By combining adaptive RAG technology with expert review, a task tree is constructed, which solves the problems of fixed strategies and fragmented modules in existing threat hunting, realizes self-feedback and self-correction of threat hunting, and improves the adaptability and quality of threat hunting.

CN121000482APending Publication Date: 2025-11-21BEIJING VENUS INFORMATION SECURITY TECH +1

Patent Information

Application Number
CN202511270726.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing threat hunting technologies rely on static rules and lack intelligent dynamic planning, resulting in fixed strategies, fragmented modules, and insufficient user interaction, making it difficult to achieve continuous optimization.

Method used

Adaptive RAG technology is introduced for task information retrieval, a task tree is constructed, and human-machine collaboration is achieved by combining expert review information, enabling self-feedback and self-correction in threat hunting.

Benefits of technology

It has improved the adaptability and integrity of threat hunting, solved the problem of human-machine separation, and enabled the continuous evolution and quality improvement of threat hunting results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000482A_ABST
    Figure CN121000482A_ABST
Patent Text Reader

Abstract

According to the threat hunting method and device, the computer storage medium and the terminal, the adaptive RAG technology is introduced for task information retrieval, the retrieval depth is determined according to the task complexity, and the threat hunting adaptability and integrity are improved; compared with the prior art that hunting processing is carried out according to tasks one by one, the embodiment of the invention constructs the task tree through the retrieved task information, obtains the original hunting data of all hunting tasks based on the task tree, and carries out hunting processing on the obtained original hunting data, so that the planning and execution separation of the threat hunting tasks is realized; when the task tree is updated, expert auditing information is introduced besides the research and judgment conclusion, a closed loop of man-machine cooperation is achieved, and the problem of man-machine splitting in the hunting process of related technologies is effectively solved; by iteratively updating the task tree, the threat hunting processing is endowed with self-feedback and self-correction capabilities, and the evolution of threat hunting results is realized; in conclusion, the threat hunting quality is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This article relates to cybersecurity technologies, particularly a method, apparatus, computer storage medium, and terminal for threat hunting. Background Technology

[0003] Threat hunting in related technologies is mostly based on static rules, log analysis, and threat intelligence matching, exhibiting a certain level of automation and intelligence. For example, the previous application CN119652660A disclosed a "Power Industry Cybersecurity Collaborative Defense System Based on Threat Hunting Technology." This solution constructs a collaborative structure including a "threat intelligence sharing platform," "log collection and analysis," and "risk visualization," relying on predefined rules and attack models for matching to achieve early warning and response to cybersecurity risks in the power industry. Although this method has a certain hierarchical structure and real-time performance, its hunting strategy is highly dependent on static rules, and the task scheduling and intelligence analysis process lacks intelligent dynamic planning capabilities. The previous application CN119835060A disclosed a "Multi-Source Log Data Fusion Subtree Source Graph Attack Detection Method Based on Active Defense." This method improves the accuracy of APT detection to some extent by constructing an "attack behavior graph" and an "log source graph" for alignment and comparison, and combining subtree isomorphism to identify suspicious behavior paths. However, its structure is relatively static, and the task execution process lacks feedback loops and adaptive mechanisms, failing to achieve dynamic strategy optimization and cross-module linkage.

[0004] In summary, threat hunting still faces numerous challenges in practical applications. First, the process typically relies on the experience of senior analysts, resulting in high barriers to entry and poor replicability. Second, hunting tasks involve the integration and analysis of multi-source heterogeneous data (such as logs, APIs, and intelligence databases), making manual processing inefficient and prone to errors. Third, the process, from task planning, data querying, result interpretation to report writing, is lengthy and complex, easily leading to a disconnect between human and machine information processing. Finally, user feedback is difficult to effectively integrate into closed-loop optimization, hindering the continuous evolution of results. In short, threat hunting methods in related technologies suffer from fixed strategies, fragmented modules, and insufficient user interaction; therefore, improving the quality of threat hunting remains an unresolved issue. Summary of the Invention

[0005] This application provides a method for threat hunting, including: On the other hand, embodiments of this application also provide a computer storage medium storing a computer program, which, when executed by a processor, implements the aforementioned threat hunting method.

[0006] Furthermore, embodiments of this application also provide a terminal, including: a memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute computer programs in memory; When the computer program is executed by the processor, it implements the threat hunting method described above.

[0007] Furthermore, embodiments of this application also provide a threat hunting apparatus, comprising: a task planner unit, a threat hunting team unit, a threat assessor unit, and a manual review unit; wherein, The task planner unit is configured to: upon receiving an alarm event from within the network, use Retrieval Enhancement Generation (RAG) technology to retrieve data from external data sources and the internal security database to obtain the task information needed to determine the hunting task, and generate a threat hunting task tree based on the obtained task information; the retrieval depth is determined according to the complexity of the hunting task; the internal security database includes: alarm events, the original alarm data of the alarm events, and the context data of the original alarm data; the external data source includes: the latest tactics, techniques, and procedures (TTP) data of network attacks outside the network, the original attack data of the network attacks, and the context data of the original attack data; when determining to update the task tree, the task tree is updated based on the assessment conclusions and expert review information; The Threat Hunting Team unit is configured to: query the internal security database based on the generated task tree to obtain the original hunting data; when the Task Planner unit updates the task tree, it will re-obtain the original hunting data based on the updated task tree. The Threat Assessor unit is configured to: process the obtained raw hunting data to obtain assessment conclusions; obtain new assessment conclusions based on the raw hunting data re-obtained by the Threat Hunting Team unit; and determine whether to update the task tree based on the obtained conclusions. The manual review unit is set up as follows: after the threat assessor unit identifies potential threats during the hunting process, it receives expert review information, which includes adjustment information for editing the task tree.

[0008] This disclosure introduces adaptive RAG technology for task information retrieval, determining the depth of task information retrieval based on task complexity, thus improving the adaptability and completeness of threat hunting. Along with related technologies, hunting is processed task-by-task. This disclosure constructs a task tree composed of hunting tasks based on the retrieved task information, obtains raw hunting data for all hunting tasks based on the task tree, and processes the obtained raw hunting data, achieving separation of threat hunting task planning and execution. When updating the task tree, in addition to the judgment conclusions, expert review information is introduced, realizing a closed loop of human-machine collaboration and effectively solving the problem of human-machine separation in threat hunting processes using related technologies. Through iterative updates to the task tree, threat hunting processing is endowed with self-feedback and self-correction capabilities, realizing the evolution of threat hunting results. In summary, the quality of threat hunting is improved.

[0009] Other features and advantages of this application will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the application. Other advantages of this application can be realized and obtained by means of the solutions described in the description and the accompanying drawings. Attached Figure Description

[0010] The accompanying drawings are used to provide an understanding of the technical solutions of this application and constitute a part of the specification. They are used together with the embodiments of this application to explain the technical solutions of this application and do not constitute a limitation on the technical solutions of this application.

[0011] Figure 1 This is a flowchart illustrating a method for threatening hunting according to an embodiment of the present disclosure; Figure 2 This is a structural block diagram of a device for threatening hunting according to an embodiment of the present disclosure; Figure 3 This is a schematic diagram of the composition of a threat hunting device with a multi-agent architecture according to an embodiment of this disclosure; Figure 4 This is a schematic diagram of the initial composition of the task tree in an embodiment of this disclosure; Figure 5 A schematic diagram of the components of the task updated for the collapse implementation. Detailed Implementation

[0012] This application describes several embodiments, but these descriptions are exemplary and not restrictive, and it will be apparent to those skilled in the art that many more embodiments and implementations are possible within the scope of the embodiments described herein. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with, or may replace, any feature or element of any other embodiment.

[0013] This application includes and contemplates combinations of features and elements known to those skilled in the art. The embodiments, features, and elements disclosed in this application can also be combined with any conventional features or elements to form unique inventive solutions. Any feature or element of any embodiment can also be combined with features or elements from other inventive solutions to form another unique inventive solution. Therefore, it should be understood that any feature shown and / or discussed in this application can be implemented individually or in any suitable combination. Therefore, the embodiments are not limited except by the limitations imposed by the appended claims and their equivalents. Furthermore, various modifications and changes can be made within the scope of the appended claims.

[0014] Furthermore, in describing representative embodiments, the specification may have presented methods and / or processes as a specific sequence of steps. However, the method or process should not be limited to the specific order of steps described herein, to the extent that it does not depend on such a specific order. As will be understood by those skilled in the art, other sequences of steps are also possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation of the claims. Moreover, the claims concerning the method and / or process should not be limited to the steps performed in the written order, and those skilled in the art will readily understand that these orders can be varied and still remain within the spirit and scope of the embodiments of this application.

[0015] This disclosure can be applied to threat hunting tasks in intranet environments. To implement subsequent threat hunting methods, the following two assumptions generally need to be met, referring to related technologies: 1. All network traffic has been uniformly collected and structured by the security system from multiple heterogeneous sources. Attack traffic and normal traffic are mixed in large-scale log data, supporting efficient retrieval and association through SQL queries, API calls, etc.; 2. Potential attack behaviors are hidden in normal operations and are difficult to fully cover through static rules. It is necessary to rely on semantic enhancement, policy optimization, and context understanding for proactive identification and response.

[0016] Figure 1A flowchart of a threat hunting method according to an embodiment of this disclosure is shown below. Figure 1 As shown, it includes: Step 101: After receiving an alarm event from within the network, the Retrieval Enhancement Generation (RAG) technique is used to retrieve data from external data sources and the internal security database to obtain the task information required to determine the hunting task. Based on the obtained task information, a task tree for threat hunting is generated. The retrieval depth is determined according to the complexity of the hunting task. The data in the internal security database includes: alarm events, the original alarm data of the alarm events, and the context data of the original alarm data. The data from external data sources includes: the latest tactics, techniques, and procedures (TTP) data of network attacks outside the network, the original attack data of network attacks, and the context data of the original attack data. Step 102: Query the internal security database based on the generated task tree to obtain the original hunting data; Step 103: Process the obtained raw hunting data to obtain an analysis conclusion; Step 104: Determine whether to update the task tree based on the obtained analysis conclusions; Step 105: When determining to update the task tree, update the task tree based on the assessment conclusion and expert review information, and re-obtain the original hunting data based on the updated task tree, and obtain new assessment conclusions based on the re-obtained original hunting data; wherein, the expert review information includes: the adjustment information received after identifying potential threats during the hunting process to edit the task tree.

[0017] This disclosure introduces adaptive RAG technology for task information retrieval, determining the depth of task information retrieval based on task complexity, thus improving the adaptability and completeness of threat hunting. Along with related technologies, hunting is processed task-by-task. This disclosure constructs a task tree composed of hunting tasks based on the retrieved task information, obtains raw hunting data for all hunting tasks based on the task tree, and processes the obtained raw hunting data, achieving separation of threat hunting task planning and execution. When updating the task tree, in addition to the judgment conclusions, expert review information is introduced, realizing a closed loop of human-machine collaboration and effectively solving the problem of human-machine separation in threat hunting processes using related technologies. Through iterative updates to the task tree, threat hunting processing is endowed with self-feedback and self-correction capabilities, realizing the evolution of threat hunting results. In summary, the quality of threat hunting is improved.

[0018] In one exemplary instance, the external data source data in this disclosure includes data from the following data sources outside the network: threat intelligence platforms, open-source intelligence, and vulnerability databases; the data coverage of the retrieved data is enhanced by using external data source data.

[0019] In one exemplary instance, the more complex the task of this disclosure embodiment, the greater the retrieval depth; the retrieval depth of this disclosure embodiment may include zero steps, single steps, or multiple steps.

[0020] In one exemplary instance, embodiments of this disclosure obtain task information needed to determine a hunting task by retrieving external data sources and internal security databases using enhanced generative arrester (RAG) technology, including: Based on event clues and the MITRE ATT&CK knowledge base, adaptive RAG retrieval technology is used to obtain task information (intelligence most closely related to the alarm event) needed to determine the hunting mission from external data sources and internal security databases. In one exemplary instance, embodiments of this disclosure may use a plan-and-execute paradigm to generate a multi-layered threat hunting task tree.

[0021] The embodiments disclosed herein enhance planning flexibility and improve task completion rates through paradigm shifts.

[0022] In one exemplary instance, embodiments of this disclosure retrieve data from external data sources and internal security databases using a search-enhanced generated RAG (Retrieval Enhancement) technique, including: A total retrieval reference score is obtained based on pre-determined complexity, novelty, event severity, and historical failure rates. The search depth is determined based on the total search reference score, and the search is performed based on the determined search depth. The smaller the total search reference score, the fewer the number of search steps; the fewer the number of search steps, the narrower the range of search data sources.

[0023] The overall score for retrieval is expressed as: score = α·complexity + β·novelty + γ·severity_n + δ·failure_n, where complexity represents the complexity index, complexity = 0.5·norm(C_len, 14) + 0.5·norm(C_branch), C_len represents the length of the technology set T_set, with a maximum value of 14, C_branch = AvgBranch(T_set, KB_attack_chain), representing the average number of branches in the historical attack chain graph KB_attack_chain that are at the same level as the T_set node, and novelty = 1 - Sim_avg, where novelty represents the novelty index, Sim_avg = CosineSim(T_set, TopK(KB_attack_chain)), Sim_avg is the average similarity between the set of attack techniques and the historical attack chain vector representation of TopK, severity_n represents the event severity index, severity_n=norm(severity,[0,1]), severity represents the event severity, the event severity index is used to map the event severity to the range of 0-1, failure_n represents the historical failure rate, α, β, γ and δ are the pre-determined weighting coefficients for each index of the total score of the retrieval reference, α+β+γ+δ=1.

[0024] In one exemplary instance, embodiments of this disclosure determine the search depth based on a total search reference score, and perform a search based on the determined search depth, including: When the total score of the search reference is less than the first preset score threshold, the search depth is determined to be 0, and the task information required to determine the hunting task is obtained by relying on the internal knowledge of the AI ​​large model (LMM). When the total score of the search reference is greater than or equal to the first preset score threshold, but less than the second preset score threshold, the search depth is determined to be 1, a single-step search is performed, and the internal security database is searched to obtain the task information required to determine the hunting task. When the total score of the search reference is greater than or equal to the second preset score threshold, the search depth is determined to be n. If n is greater than 1, a multi-step search with fewer than n steps is performed to search the internal security database and external data sources to obtain the task information required to determine the hunting task.

[0025] This embodiment of the disclosure enhances the accuracy and completeness of hunting mission planning by obtaining a total search reference score, determining the search depth based on the total search reference score, and performing a search based on the determined search depth.

[0026] In one exemplary instance, embodiments of this disclosure query internal security database data based on a generated task tree to obtain raw hunting data, including: Construct execution prompts based on the Situation-Task-Action-Result-Reflection (STARR) paradigm; Combine the constructed execution prompts with the task sequence confirmed by the task tree to construct the API executor and the SQL executor respectively. API executors use TEXT2API technology to call external threat intelligence sources, while SQL executors use TEXT2SQL technology to query internal security databases to obtain raw hunting data.

[0027] Through the above processing, the hunting task is transformed into SQL queries and API calls using the STARR principle paradigm. By integrating the Reflexion mechanism, it is endowed with the ability to self-feedback and self-correct. In the face of abnormal situations, it can automatically recover and optimize without manual intervention, ensuring the smooth execution of the hunting task.

[0028] In one exemplary instance, the API executor reference is constructed through the following process: A Python script is generated based on the task description of the hunting task contained in the task tree, and the generated Python script calls the internal / external security tool API (IP reputation, hash, domain C2, etc.). The internal / external security tool API is used to retrieve the internal security database. Run code in an isolated sandbox to retrieve internal security databases and record execution results, including requests and responses, in real time; Based on the execution results and logs in the internal security database, if the execution results meet the preset goals, the Python script will call the internal / external security tool API to determine the API executor. If the execution results do not meet the preset goals, the Python script will be adjusted and retried until the execution results meet the preset goals or the number of retries reaches the preset number. In this case, the internal / external security tool API called by the Python script will be determined as the API executor.

[0029] This disclosure uses the CodeACT agent design paradigm to construct API executors; it runs code in an isolated sandbox, eliminating potential risks to the main system.

[0030] In one exemplary instance, the SQL executor is constructed through the following processing: In the CodeACT executable code-as-action agent paradigm, agents are driven to invoke tools and execute control flows. Combining the Text-to-SQL method in DAIL-SQL, a first retrieval query is generated on a unified model of data sources across Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and Network Traffic Analysis (NetFlow) that is pre-aligned and accessible by a single SQL entry point. The first retrieval query is used to retrieve internal security databases. The generated first search query is used to execute a query on the internal security database within the controlled database sandbox and leave a trace, thus obtaining the query results. Based on the query results and logs in the internal security database, if the query results meet the preset query objectives, the first search query is designated as the SQL executor. If the query results do not meet the preset query objectives, the first search query is adjusted and retried until the query results meet the preset query objectives or the number of retries reaches the preset number, at which point the first search query is designated as the SQL executor.

[0031] This disclosure employs the DAIL-SQL algorithm to enhance the accuracy of SQL query generation. DAIL-SQL is an efficient Text-to-SQL generation method that leverages the few-shot learning capability of the AI ​​Large Model (LLM) by selecting example pairs (question-SQL pairs) with similar structures to the target question as prompts to optimize the SQL generation quality of the AI ​​Large Model. Query execution and logging within a controlled database sandbox ensure the security of business data.

[0032] In one exemplary instance, embodiments of this disclosure perform hunting processing based on obtained raw hunting data to obtain an assessment conclusion, including: Inferences are drawn from the raw hunting data to identify potential threats; The identified potential threats are analyzed to obtain an assessment conclusion.

[0033] In one exemplary instance, embodiments of this disclosure perform inference on obtained raw hunting data to identify potential threats, including: By combining TTP association, behavioral pattern recognition, and anomaly detection algorithms, inferences are made on raw hunting data to identify potential threats.

[0034] In one exemplary instance, embodiments of this disclosure pre-set Sigma (for log behavior) and YARA (for file or sample content) static rule matching, using a unified DSL to filter the raw hunting data, which has quickly screened out obviously normal or known malicious events. Combined with a large AI model and a small number of pre-set examples, it uses similarity inference and unknown pattern detection.

[0035] In one exemplary instance, this disclosure embodiment updates the task tree based on the assessment conclusion and expert review information, including: If an attack is successfully detected in a hunting mission in the mission tree, the hunting mission is retained. If, based on the assessment conclusions or expert review information, it is determined that no aggressive behavior was detected in the hunting mission, then the hunting mission will be removed from the mission tree. If the assessment concludes that the hunting mission resulted in uncertain attack behavior (vague or undetermined attack behavior), then the hunting mission will be updated and / or additional hunting missions will be added based on the expert review information.

[0036] In one exemplary instance, this disclosure embodiment determines whether to update the task tree based on the obtained assessment conclusion, including: Once the assessment results indicate that all hunting tasks in the task tree have been completed, the task tree will stop being updated.

[0037] When there are incomplete tasks in the task tree of this disclosure embodiment, the judgment conclusion may include insufficient evidence or an incomplete attack chain.

[0038] In one exemplary instance, the method of this disclosure embodiment further includes: When the number of times the task tree is updated reaches a preset threshold, the task tree updates will stop.

[0039] In one exemplary instance, the method of this disclosure embodiment further includes: When it is determined that the task tree will no longer be updated, a threat hunting report will be generated based on the last assessment conclusion.

[0040] In one exemplary instance, embodiments of this disclosure modify or fine-tune the system's hunting tasks by adding or deleting hunting tasks, adjusting hunting task priorities, or supplementing detection logic through expert review information, thereby achieving RLHF-style quality control.

[0041] In one exemplary instance, this disclosure embodiment generates a threat hunting report based on the last assessment conclusion, including: Based on the analysis results, the attack chain is reconstructed according to the attack sequence confirmed by the task tree, and a threat hunting report is generated that includes attack steps, affected assets, threat indicators and protection recommendations.

[0042] In one exemplary instance, the method of this disclosure embodiment further includes: A visualized attack chain diagram is provided to the user based on the attack steps, affected assets, and threat indicators.

[0043] This disclosure also provides a computer storage medium storing a computer program, which, when executed by a processor, implements the aforementioned threat hunting method.

[0044] This disclosure also provides a terminal, including: a memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute computer programs in memory; The computer program implements the threat hunting method described above when executed by the processor.

[0045] Figure 2 This is a structural block diagram of a device for threatening hunting according to an embodiment of the present disclosure, as shown below. Figure 2 As shown, it includes: a task planner unit, a threat hunting team unit, a threat assessor unit, and a human review unit; among which, The task planner unit is configured to: upon receiving an alarm event from within the network, use Retrieval Enhancement Generation (RAG) technology to retrieve data from external data sources and the internal security database to obtain the task information needed to determine the hunting task, and generate a threat hunting task tree based on the obtained task information; the retrieval depth is determined according to the complexity of the hunting task; the internal security database includes: alarm events, the original alarm data of the alarm events, and the context data of the original alarm data; the external data source includes: the latest tactics, techniques, and procedures (TTP) data of network attacks outside the network, the original attack data of the network attacks, and the context data of the original attack data; when determining to update the task tree, the task tree is updated based on the assessment conclusions and expert review information; The Threat Hunting Team unit is configured to: query the internal security database based on the generated task tree to obtain the original hunting data; when the Task Planner unit updates the task tree, it will re-obtain the original hunting data based on the updated task tree. The Threat Assessor unit is configured to: process the obtained raw hunting data to obtain assessment conclusions; obtain new assessment conclusions based on the raw hunting data re-obtained by the Threat Hunting Team unit; and determine whether to update the task tree based on the obtained conclusions. The manual review unit is set up as follows: after the threat assessor unit identifies potential threats during the hunting process, it receives expert review information, which includes adjustment information for editing the task tree.

[0046] In one exemplary instance, the task planner unit of this disclosure embodiment is configured to retrieve external data source data and an internal security database by using retrieval enhancement generation RAG technology, including: A total retrieval reference score is obtained based on pre-determined complexity, novelty, event severity, and historical failure rates. The search depth is determined based on the total search reference score, and the search is performed based on the determined search depth. The smaller the total search reference score, the fewer the number of search steps; the fewer the number of search steps, the narrower the range of search data sources.

[0047] The overall score for retrieval is expressed as: score = α·complexity + β·novelty + γ·severity_n + δ·failure_n, where complexity represents the complexity index, complexity = 0.5·norm(C_len, 14) + 0.5·norm(C_branch), C_len represents the length of the technology set T_set, with a maximum value of 14, C_branch = AvgBranch(T_set, KB_attack_chain), representing the average number of branches in the historical attack chain graph KB_attack_chain that are at the same level as the T_set node, and novelty = 1 - Sim_avg, where novelty represents the novelty index, Sim_avg = CosineSim(T_set, TopK(KB_attack_chain)), Sim_avg is the average similarity between the set of attack techniques and the historical attack chain vector representation of TopK, severity_n represents the event severity index, severity_n=norm(severity,[0,1]), severity represents the event severity, the event severity index is used to map the event severity to the range of 0-1, failure_n represents the historical failure rate, α, β, γ and δ are the pre-determined weighting coefficients for each index of the total score of the retrieval reference, α+β+γ+δ=1.

[0048] In one exemplary instance, determining the search depth based on the total search reference score and performing a search based on the determined search depth includes: When the total score of the search reference is less than the first preset score threshold, the search depth is determined to be 0, and the task information required to determine the hunting task is obtained by relying on the internal knowledge of the AI ​​large model. When the total score of the search reference is greater than or equal to the first preset score threshold, but less than the second preset score threshold, the search depth is determined to be 1, a single-step search is performed, and the internal security database is searched to obtain the task information required to determine the hunting task. When the total score of the search reference is greater than or equal to the second preset score threshold, the search depth is determined to be n. If n is greater than 1, a multi-step search with fewer than n steps is performed to search the internal security database and external data sources to obtain the task information required to determine the hunting task.

[0049] In one exemplary instance, the threat hunting team unit of this disclosure embodiment is configured to: query internal security database data based on the generated task tree to obtain raw hunting data, including: Construct execution prompts based on the context-task-action-result-reflection paradigm; Combine the constructed execution prompts with the task sequence confirmed by the task tree to construct API executors and SQL executors respectively; API executors use TEXT2API technology to call external threat intelligence sources, while SQL executors use TEXT2SQL technology to query internal security databases to obtain raw hunting data.

[0050] In one exemplary instance, the SQL executor of this disclosure is constructed through the following processing: In CodeACT’s executable code as action agent paradigm, agents are driven to invoke tools and execute control flow. Combined with the Text-to-SQL method in DAIL-SQL, a first retrieval query is generated on a unified model of data sources across Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and Network Traffic Analysis (NetFlow) that is pre-aligned and accessible by a single SQL entry point. The first retrieval query is used to retrieve the internal security database. The generated first search query is used to execute a query on the internal security database within the controlled database sandbox and leave a trace, thus obtaining the query results. Based on the query results and logs in the internal security database, if the query results meet the preset query objectives, the first search query is designated as the SQL executor. If the query results do not meet the preset query objectives, the first search query is adjusted and retried until the query results meet the preset query objectives or the number of retries reaches the preset number, at which point the first search query is designated as the SQL executor.

[0051] In one exemplary instance, the threat assessor unit of this disclosure is configured to perform hunting processing based on the obtained raw hunting data to obtain an assessment conclusion, including: Inferences are drawn from the raw hunting data to identify potential threats; Assess the identified potential threats and obtain assessment conclusions; This includes reasoning from the obtained raw hunting data to identify potential threats, including: using a combination of TTP association, behavioral pattern recognition, and anomaly detection algorithms to reason from the raw hunting data and identify potential threats.

[0052] In one exemplary instance, the threat assessor unit of this disclosure is configured to determine whether to update the task tree based on the obtained assessment conclusion, including: Once the assessment results indicate that all hunting tasks in the task tree have been completed, the task tree will stop being updated.

[0053] In one exemplary instance, the threat assessor unit of this disclosure is further configured to: stop updating the task tree when the number of updates to the task tree reaches a preset threshold.

[0054] In one embodiment of this disclosure, the task planner unit is configured to update the task tree based on the assessment conclusions and expert review information, including: If an attack is successfully detected in a hunting mission in the mission tree, the hunting mission is retained. If, based on the assessment conclusions or expert review information, it is determined that no aggressive behavior was detected in the hunting mission, then the hunting mission will be removed from the mission tree. If the assessment concludes that the hunting mission will result in uncertain attack behavior, the hunting mission will be updated and / or additional hunting missions will be added based on expert review information.

[0055] The following application examples briefly illustrate the embodiments of this disclosure. These application examples are only used to illustrate the embodiments of this disclosure and are not intended to limit the scope of protection of the embodiments of this disclosure.

[0056] Application Examples This disclosure, through the introduction of adaptive RAG, achieves dynamic fusion of threat intelligence, user objectives, and context, breaking through the traditional static rule-driven model and supporting the automatic formulation and real-time adjustment of hunting strategies. It constructs a heterogeneous team composed of intelligent agents such as coordinators, planners, executors, and analysts, adopting a clearly defined, autonomous, and collaborative structure to improve parallel task processing and complex scenario handling capabilities. It achieves modular collaborative task execution, enhancing parallel task processing and complex scenario handling capabilities. A human feedback mechanism is introduced, embedding user review opinions into the process, driving the continuous evolution of system strategies and results, enhancing decision-making transparency and controllability, and improving the credibility and adaptability of the final results. It possesses proactive threat hunting capabilities including dynamic task planning, automated task execution, and dynamic optimization based on expert feedback, thereby supporting the construction of a new generation of network security defense systems.

[0057] The threat hunting apparatus of this disclosure can be implemented based on a multi-agent architecture to obtain... Figure 3 The multi-agent hybrid threat hunter (MAHTH) device shown is an example of such a device. Figure 3 As shown, it includes: an external data source, an internal storage layer, an agent execution layer, an agent orchestration layer, and a manual review node; among which, The agent orchestration layer includes a coordinator agent and a task planning agent. The agent execution layer includes: API Executor hunting agent, SQL Executor hunting agent, threat analysis agent (Analyzer), and attack chain reconstruction agent (Reconstructor). The Coordinator agent is responsible for communicating with users to clarify their needs and define boundaries and expected outputs. This includes receiving event cues from user input, extracting elements such as source and event description using semantic parsing, and clarifying boundaries and expected outputs (for task iteration and incremental hunting) through communication with users. Clarifying boundaries and expected outputs includes determining the conditions for stopping task tree updates. The task planning agent (Planner, corresponding to the task planner unit in the embodiments of this disclosure): constructs a structured threat hunting task tree.

[0058] The hunting team (Executor, corresponding to the threat hunting team unit in the embodiments of this disclosure) includes two agents: APIExecutor hunting agent (API executor) and SQLExecutor hunting agent (SQL executor), which perform cross-source data retrieval.

[0059] The threat analysis agent (Analyzer, corresponding to the threat analyzer unit in the embodiments of this disclosure) performs threat analysis on the hunting data and obtains analysis conclusions.

[0060] The manual review node (Review, corresponding to the manual review unit in the embodiments of this disclosure) provides a quality assurance mechanism for task plan review, task execution result verification, and expert feedback.

[0061] Attack Chain Reconstructor: Reconstructs the complete attack chain sequence based on the hunting results, generating a structured threat hunting report.

[0062] External data sources include data from the following sources outside the network: threat intelligence platforms, open-source intelligence, and vulnerability databases.

[0063] The internal storage layer includes an internal security database (Security DB), a hunting path graph database (ThreatVector DB), and a task state database (Task State DB). The internal security database stores alarm events and raw context data for Executor integration and retrieval. The hunting path graph database stores known / historical attack links for task planners to retrieve and reuse typical path templates when generating hunting hypotheses. The task state database stores the task tree, the execution status, time, results, and manual review nodes' read plan modification trajectory for each node.

[0064] In one exemplary instance, this disclosure uses a TAG prompting framework to construct a prompting word p_coordinate according to the (Task → Action → Goal) paradigm to build an intelligent coordinator. This coordinator possesses domain semantic understanding capabilities and is used for real-time parsing of user intent and feature extraction. Event clues are input in a JSON structure, and clue features are extracted. If key domains are missing or conflicting, the coordinator dynamically asks questions according to the dialogue strategy until the output specifications are met.

[0065] In one exemplary instance, embodiments of this disclosure can use the TRACE cue word framework to construct the task planning cue word p_planner according to the (Task → Request → Action → Context → Example) paradigm, thus constructing a task planner. The Planner agent uses the Plan-and-Execute paradigm to generate a multi-level, structured threat hunting task tree, which helps to enhance planning flexibility and improve task completion rate.

[0066] In one exemplary instance, embodiments of this disclosure use the CRISPE cue word framework to construct the analysis cue word p_analyzer according to the (Context-Role-Input-Steps-Purpose-Example) paradigm, construct a threat analyzer agent (Analyzer), and combine a multi-source dataset (data_pool) and ATT&CK tactics to analyze and judge the hunting results.

[0067] In one exemplary instance, this disclosure uses the TRACE cue word framework to construct the cue word p_reconstructor according to the (Task → Request → Action → Context → Example) paradigm, and combines the threat assessment results and the original threat clues to construct the attack chain reconstructor.

[0068] The MAHTH embodiment disclosed herein adopts a multi-agent distributed task architecture, which decomposes the threat hunting process into independent stages such as "coordination-planning-execution-analysis-reporting". Each stage is handled by a dedicated agent, which greatly improves task processing efficiency and system maintainability.

[0069] The following code examples illustrate the application of RAG-based retrieval in the embodiments of this disclosure, including: Phase 1, Feature Preparation Phase, code as follows: 1: C_len ← |T_set| / / The length of the technique set T_set (the number of techniques involved in the attack chain), used to measure the task size / complexity; the maximum is 14, corresponding to the 14 tactics of ATT&CK; 2: C_branch ← AvgBranch(T_set, KB_attack_chain) / / Counts the average number of branches (parallel techniques) at the same level as the T_set node in the historical attack chain graph library KB_attack_chain. If there is no historical data, the default value is 1; 3: Sim_avg ← CosineSim(T_set, TopK(KB_attack_chain)) / / Calculates the average TopK similarity between the set of techniques and the vector representation of historical attack chains, measuring how close the current task is to known patterns; 4:complexity← 0.5·norm(C_len,14)+0.5·norm(C_branch) / / Complexity metric: Combining attack chain length (C_len) and average number of branches (C_branch), normalized and then taken as an equal-weighted average; 5:novelty ← 1-Sim_avg / / Novelty index: The less similar to historical links, the higher the novelty, that is, the rarer / unknown the attack pattern; 6: severity_n ← norm(severity, [0,1]) / / Maps the severity of an event to a range of 0-1, for example: low = 0.2, medium = 0.5, high = 0.8, urgent = 1.0; 7:failure_n ← f / / Historical failure rate f is used directly (already maintained in the database), representing the proportion of similar searches / tasks that failed in the past; 8: score ← α·complexity + β·novelty + γ·severity_n + δ·failure_n / / The final retrieval reference score is obtained by combining four indicators, ranging from [0,1], / / α+β+γ+δ=1, used to adjust the importance of different dimensions; Phase 2, Depth Determination Phase, includes: 9: if score < τ0 then / / If the total score for the retrieval reference is lower than the threshold τ0 (default 0.25), it indicates that the task is simple / common / low-risk; 10:d* ← 0 / / Set the search depth to 0, and directly rely on the internal knowledge of the large AI model; 11: else if score < τ1 then / / If the total score is between τ0 and τ1 (default 0.55), it means the task has a certain complexity / novelty, but no external multi-step retrieval is required; 12:d* ← 1 / / Set the search depth to 1 and perform a single-step search (internal security database); 13:else / / If score ≥ τ1, it indicates that the task is highly complex, rare, or serious, requiring multiple steps of retrieval to obtain more comprehensive information; 14:d* ← min(d*, D_max) / / Select multi-step retrieval (internal secure database + external data source), the number of steps does not exceed the maximum depth D_max; 15:end if Phase 3, the dynamic retrieval phase, includes: 16:K ← ; Π ← InitPlan(T_set | E) / / Initialization: The knowledge block set K is empty, and the initial task plan Π is generated based on T_set and event clues E; 17: if d* = 0 then / / Zero-step retrieval: indicates complete reliance on the knowledge of the large AI model itself; 18: Π ← LLMPlan(T_set) / / The AI ​​model directly generates the task tree for hunting based on T_set, without performing external retrieval, suitable for common patterns; 19:else / / Single-step or multi-step retrieval; 20:q_vec ← QueryRewrite(Π, T_set, step=1) / / Rewrite the query statement q_vec (used for vector retrieval); 21: C_vec ← Retrieve(VectorStore, q_vec) / / Retrieves document block C_vec from a private vector store; 22:K ← K∪C_vec ; Π ← UpdatePlan(Π, C_vec) / / Merge the retrieved knowledge blocks into K and update the task plan Π (e.g., supplement detection logic or data source); 23:for step = 2 to d* do; 24:q_web ← QueryRewrite(Π, T_set, step) / / Rewrite the query statement q_web (for web retrieval); 25:C_web ← Retrieve(WebSearch, q_web) / / Retrieves the latest document block C_web from an external data source; 26:K ← K ∪ C_web ; Π ← UpdatePlan(Π, C_web) / / Merge the external data source retrieval results into K, update the task tree Π, and combine highly relevant (internal data) and highly fresh (external data) content.

[0070] In this embodiment of the disclosure, during the feature preparation stage, the system first extracts several feature indicators from the input event clues and the mapped ATT&CK technology set, including: technology chain length: the number of technologies involved in the event, used to measure the task scale; branch complexity: by comparing with historical attack chains, the number of parallel technologies in the same layer is counted, reflecting the branch complexity of the task; similarity index: calculating the similarity between the current task and historical attack chains, if the similarity is low, it indicates that the event is relatively novel; event severity: mapping the event urgency level (such as low, medium, high, urgent) to floating-point numbers of 0-1; historical failure rate: recording the proportion of failed retrievals in similar tasks in the past, used to reflect the reliability of the system; the system performs a weighted calculation of the above indicators to obtain a total score, which is used to determine the depth of subsequent retrieval.

[0071] In this embodiment of the disclosure, during the depth judgment stage, the calculated score is compared with two preset thresholds: if the score is low (below the first threshold), it indicates that the task is a common, low-risk event, and the system does not need to perform external retrieval, but can rely solely on the built-in knowledge of the model; if the score is medium (between the first and second thresholds), it indicates that the task has a certain degree of complexity or novelty, and the system will perform a vector library retrieval to obtain additional information from the existing internal security database; if the score is high (above the second threshold), it indicates that the task is complex and important, and the system will enter a multi-step retrieval process, accessing external network intelligence sources for information supplementation in addition to the internal security database.

[0072] In this embodiment, during the dynamic retrieval phase, the system performs different levels of retrieval based on the aforementioned determination results: 1. Zero-step retrieval: Directly generates a task tree using the model, requiring no external information, suitable for common and highly repetitive attack patterns; 2. Single-step retrieval: The system first generates a retrieval statement for the task, performs a search in the internal security database to obtain relevant documents or knowledge blocks, and adds them to the task tree; 3. Multi-step retrieval: The system first performs a search in the internal security database, and then in subsequent steps, dynamically generates query statements based on the updated task tree, performing real-time searches on external data sources (e.g., threat intelligence from the most recent day / month / year). Each retrieval result is incorporated into the knowledge set and used to update the task plan until the preset maximum retrieval depth is reached.

[0073] In this embodiment of the disclosure, a task tree is output during the result output stage.

[0074] The task tree in this embodiment is a hunting action structure with branches and depth, where each node represents a hunting task, and each node corresponds to a hunting analysis unit (including attack techniques, detection actions, etc.). See also Figure 4 In this embodiment, the nodes in the task tree are connected by causal or sequential relationships to express the hunting link logic; the structure can be regarded as a directional parse tree that supports branch parallelism and hierarchical deepening.

[0075] See Figure 5 In this disclosure, if it is determined that the task tree needs to be updated, the task tree is edited based on the assessment conclusion and expert review information, including: If a task node successfully detects an attack while executing a hunting task according to the task tree, it continues to execute the next task node in the task tree; for example, after completing hunting tasks 1 and 2 step by step, hunting tasks 3.1, 3.2, and 3.3 are processed. If, based on the assessment or expert review, it is determined that no aggressive behavior was detected during the hunting mission, then the mission node and its related links are removed from the mission tree; for example... Figure 5 Hunting mission 4.2 has been removed; If the detection result of the task node indicates the presence of ambiguous or uncertain attack behavior, the task tree will be edited based on the expert review information: the content of the task node will be modified or relevant sub-task nodes will be added to further capture potential threats; for example, hunting task 3.3 will be changed to hunting task 3.3.1; hunting task 4.3 and hunting task 4.4 will be added. After completing the above editing, the task tree is updated; in this embodiment of the disclosure, the original hunting data is re-acquired and new judgment conclusions are generated for the updated task tree.

[0076] It will be understood by those skilled in the art that all or some of the steps, systems, or apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term "computer storage medium" includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

Claims

1. A method of threatening hunting, characterized in that, include: Upon receiving an alarm event from within the network, the system uses Retrieval Enhancement Generation (RAG) technology to retrieve data from external data sources and the internal security database to obtain the task information needed to determine the hunting mission. Based on the obtained task information, a threat hunting task tree is generated. The retrieval depth is determined according to the complexity of the hunting mission. The internal security database includes: alarm events, the original alarm data of the alarm events, and the context data of the original alarm data. The external data source includes: the latest tactics, techniques, and procedures (TTP) data of network attacks outside the network, the original attack data of the network attacks, and the context data of the original attack data. The original hunting data is obtained by querying the internal security database based on the generated task tree. The original hunting data is processed to obtain analytical conclusions. Determine whether to update the task tree based on the obtained analysis conclusions; When determining to update the task tree, the task tree is updated based on the assessment conclusions and expert review information. The original hunting data is then re-obtained based on the updated task tree, and new assessment conclusions are obtained based on the re-obtained original hunting data. The expert review information includes: the adjustment information received after identifying potential threats during the hunting process, which is used to edit the task tree.

2. The method according to claim 1, characterized in that, The method of generating RAG through enhanced retrieval, which retrieves data from external data sources and internal security databases, includes: A total retrieval reference score is obtained based on pre-determined complexity, novelty, event severity, and historical failure rates. The search depth is determined based on the total search reference score, and the search is performed based on the determined search depth. The smaller the total search reference score, the fewer the number of search steps; the fewer the number of search steps, the narrower the range of search data sources. The overall score for retrieval is expressed as: score = α·complexity + β·novelty + γ·severity_n + δ·failure_n, where complexity represents the complexity index, complexity = 0.5·norm(C_len, 14) + 0.5·norm(C_branch), C_len represents the length of the technology set T_set, with a maximum value of 14, C_branch = AvgBranch(T_set, KB_attack_chain), representing the average number of branches in the historical attack chain graph KB_attack_chain that are at the same level as the T_set node, and novelty = 1 - Sim_avg, where novelty represents the novelty index, Sim_avg = CosineSim(T_set, TopK(KB_attack_chain)), Sim_avg is the average similarity between the set of attack techniques and the historical attack chain vector representation of TopK, severity_n represents the event severity index, severity_n=norm(severity,[0,1]), severity represents the event severity, the event severity index is used to map the event severity to the range of 0-1, failure_n represents the historical failure rate, α, β, γ and δ are the pre-determined weighting coefficients for each index of the total score of the retrieval reference, α+β+γ+δ=1.

3. The method according to claim 2, characterized in that, The process of determining the search depth based on the overall search reference score and performing the search based on the determined search depth includes: When the total score of the search reference is less than the first preset score threshold, the search depth is determined to be 0, and the task information required to determine the hunting task is obtained by relying on the internal knowledge of the AI ​​large model LMM. When the total score of the search reference is greater than or equal to the first preset score threshold, but less than the second preset score threshold, the search depth is determined to be 1, a single-step search is performed, and the internal security database is searched to obtain the task information required to determine the hunting task. When the total score of the search reference is greater than or equal to the second preset score threshold, the search depth is determined to be n. If n is greater than 1, a multi-step search with fewer than n steps is performed to search the internal security database and external data sources to obtain the task information required to determine the hunting task.

4. The method according to claim 1, characterized in that, The step of querying the internal security database based on the generated task tree to obtain the original hunting data includes: Construct execution prompts based on the context-task-action-result-reflection paradigm; The constructed execution prompt words are combined with the task sequence confirmed according to the task tree to construct API executors and SQL executors respectively; The API executor uses TEXT2API technology to call external threat intelligence sources, and the SQL executor uses TEXT2SQL technology to query internal security database data to obtain the raw hunting data.

5. The method according to claim 4, characterized in that, The SQL executor is constructed through the following process: In CodeACT’s executable code as action agent paradigm, agents are driven to invoke tools and execute control flow. Combined with the Text-to-SQL method in DAIL-SQL, a first retrieval query is generated on a unified model of data sources across Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and Network Traffic Analysis (NetFlow) that is pre-aligned and accessible by a single SQL entry point. The first retrieval query is used to retrieve the internal security database. The generated first search query is used to execute a query on the internal security database within the controlled database sandbox and leave a trace, thus obtaining the query results. Based on the query results and logs in the internal security database, if the query results meet the preset query target, the first search query will be identified as the SQL executor. Based on the query results and logs in the internal security database, if it is determined that the query results do not meet the preset query target, the first search query is adjusted and retried until the query results meet the preset query target or the number of retries reaches the preset number. Then, the first search query is determined as the SQL executor.

6. The method according to claim 1, characterized in that, The process of processing the obtained raw hunting data to arrive at an assessment conclusion includes: The obtained raw hunting data is used to infer potential threats; Assess the identified potential threats and obtain assessment conclusions; The inference process based on the obtained raw hunting data includes: using a combination of TTP association, behavioral pattern recognition, and anomaly detection algorithms to infer the raw hunting data and identify the potential threats.

7. The method according to any one of claims 1 to 6, characterized in that, The step of determining whether to update the task tree based on the obtained analysis conclusions includes: When it is determined, based on the obtained analysis, that all hunting tasks in the task tree have been completed, the task tree will stop being updated.

8. The method according to any one of claims 1 to 6, characterized in that, The task tree update based on the assessment conclusions and expert review information includes: When an attack is successfully detected in a hunting task in the task tree, the hunting task is retained. If, based on the assessment conclusions or expert review information, it is determined that no aggressive behavior was detected in the hunting mission, then the hunting mission will be removed from the mission tree. If the assessment concludes that the hunting mission will result in uncertain attack behavior, the hunting mission will be updated and / or additional hunting missions will be added based on expert review information.

9. The method according to claim 7, characterized in that, When determining whether to update the task tree based on the obtained analysis conclusions, the method further includes: When the number of updates to the task tree reaches a preset threshold, the update of the task tree is stopped.

10. A computer storage medium storing a computer program that, when executed by a processor, implements the threat hunting method as described in any one of claims 1 to 9.

11. A terminal, comprising: A memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute computer programs in memory; When the computer program is executed by the processor, it implements the threat hunting method as described in any one of claims 1 to 9.

12. A device for threatening hunting, comprising: The unit comprises a task planner unit, a threat hunting team unit, a threat assessor unit, and a human review unit; among them, The task planner unit is configured to: upon receiving an alarm event from within the network, use Retrieval Enhancement Generation (RAG) technology to retrieve data from external data sources and the internal security database to obtain the task information needed to determine the hunting task, and generate a threat hunting task tree based on the obtained task information; the retrieval depth is determined according to the complexity of the hunting task; the internal security database includes: alarm events, the original alarm data of the alarm events, and the context data of the original alarm data; the external data source includes: the latest tactics, techniques, and procedures (TTP) data of network attacks outside the network, the original attack data of the network attacks, and the context data of the original attack data; when determining to update the task tree, the task tree is updated based on the assessment conclusions and expert review information; The Threat Hunting Team unit is configured to: query the internal security database based on the generated task tree to obtain the original hunting data; when the Task Planner unit updates the task tree, it will re-obtain the original hunting data based on the updated task tree. The Threat Assessor unit is configured to: process the obtained raw hunting data to obtain assessment conclusions; obtain new assessment conclusions based on the raw hunting data re-obtained by the Threat Hunting Team unit; and determine whether to update the task tree based on the obtained conclusions. The manual review unit is set up as follows: after the threat assessor unit identifies potential threats during the hunting process, it receives expert review information, which includes adjustment information for editing the task tree.

Citation Information

Patent Citations

  • Power industry network security collaborative defense system based on threat hunting technology

    CN119652660A

  • Multi-source log data fusion subtree traceability graph attack detection method based on active defense

    CN119835060A

Cited By

  • A threat hunting method, device, computer storage medium and terminal

    CN122419876A