Intelligent traceability method and system based on attack association analysis and processor
By collecting information from multi-source heterogeneous data to construct a knowledge graph and performing attack correlation analysis, the problems of long time consumption and high false alarm rate in existing network attack attribution are solved, and fast and accurate attack attribution is achieved.
Patent Information
- Application Number
- CN202511338454.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2025-12-12
AI Technical Summary
Existing security detection systems are unable to effectively gain a global understanding of complex network attacks, resulting in time-consuming network security incident analysis with a high false alarm rate, and a lack of automated and rapid and accurate attack attribution capabilities.
By collecting cybersecurity information from multi-source heterogeneous data, preprocessing it to construct a knowledge graph, and using knowledge reasoning and optimization mechanisms to conduct attack event correlation analysis to determine the attack source and risk.
It enables automated, rapid, and accurate attack attribution, reducing manual analysis time and improving the accuracy and efficiency of attack event location.
Smart Images

Figure CN121125258A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and more specifically to an intelligent attribution method, system, and processor based on attack correlation analysis. Background Technology
[0002] With the evolution of cyberattack techniques, sophisticated attack methods such as Advanced Persistent Threats (APTs) and multi-stage attacks are emerging in an endless stream, posing a severe challenge to traditional security defense systems. Existing security detection systems (such as IDS, IPS, and firewalls) typically generate alerts based on signature matching or simple rules. These alerts are often isolated and fragmented, lacking insight into the entire attack chain.
[0003] Currently, for common network security incidents within the State Grid system, it takes at least 3 to 5 hours from monitoring and discovery to manual analysis. This requires analyzing a large number of alarm events and network security monitoring data to locate the key information of the security incident. Furthermore, there are still a large number of false alarms in the system, and selecting the correct information from them is also a very labor-intensive task. Therefore, it is necessary to build a network security attack tracing model to automate the analysis and quickly and accurately trace the source of attacks. Summary of the Invention
[0004] The purpose of this invention is to provide an intelligent tracing method, system, and processor based on attack correlation analysis. This intelligent tracing method can automatically analyze attack events and quickly and accurately trace the source of attacks.
[0005] To achieve the above objectives, embodiments of the present invention provide an intelligent attribution method based on attack correlation analysis, the intelligent attribution method comprising: Systematically collect cybersecurity-related information from multi-source heterogeneous data; The collected network security-related information is preprocessed; Entity relationships are extracted based on the preprocessed network security-related information to construct a knowledge graph; By setting up knowledge reasoning and optimization mechanisms, the knowledge graph is optimized to ensure that it can accurately reflect the complexity and dynamism of the cybersecurity field. The attack events are acquired and correlated with the knowledge graph to perform path reconstruction and source point localization. Based on the correlation analysis between the attack source path and origin and the knowledge graph, a security event correlation analysis is performed on the attack event to determine the risk of the attack event.
[0006] Optionally, the network security related information includes: vulnerability databases, attack databases, and open datasets.
[0007] Optionally, the collected network security-related information may be preprocessed, including: The network security-related information is obtained, and meaningless tags in the network security-related information are removed by regular expressions, so that only the plain text of the network security-related information is obtained. After obtaining the plain text information related to network security, the network security information is deduplicated and the field names and content are standardized using a hash algorithm. After standardization, the network security-related information is segmented and stop words are removed.
[0008] Optionally, entity relationships are extracted based on the preprocessed network security-related information to construct a knowledge graph, including: Obtain the preprocessed network security-related information and locate the start and end positions of the entities in the network security-related information. The identified entities are assigned to corresponding predefined labels; The network security-related information, which includes the labeled entities, is input into BERT, and the output is classified into relationships to determine the semantic relationship between any two entities in the sentence, thereby determining the triples in the network security-related information. Obtain the triplet and link the entity in the network security-related information to the unique and correct entity in the knowledge base; The weight of the relationship between two entities is determined by a trust assessment method; Store the triples with entity links and confirmed weights in the graph database; A knowledge graph is constructed based on the triples in the graph database.
[0009] Optionally, the knowledge graph can be optimized by setting knowledge reasoning and optimization mechanisms to ensure that it accurately reflects the complexity and dynamism of the cybersecurity field, including: The knowledge graph and network security-related information are obtained, and logical tasks are processed based on the OWL2 inference engine. The potential relationships between entities are mined by relying on Cypher query and machine learning (such as neural networks). The knowledge graph is queried using a graph embedding algorithm to fill in missing attributes and identify similar nodes in the knowledge graph. Merge similar nodes and edges in the knowledge graph; Real-time knowledge injection is achieved through Kafka to continuously update the knowledge graph.
[0010] Optionally, attack events are acquired, and the attack events are correlated with the knowledge graph for path reconstruction and source location, including: By using security device alarms, log and traffic analysis, server resource anomaly detection, and real-time monitoring of honeypot systems and email phishing, the attack behavior and source IP can be initially located. Based on the initial identification of the attack behavior and source IP, we conducted correlation queries with external threat information and used JSONP traversal technology to obtain the attacker's host and social information. Based on the attacker's attack behavior, source IP and host, and social information, construct a complete attacker profile that includes network proxy, real identity, contact information, and organizational background; Based on the correlation analysis between the attacker profile and the knowledge graph, the attacker's attack path, attack methods, and attack sources are determined.
[0011] Optionally, based on the correlation analysis between the attack source path and origin and the knowledge graph, a security event correlation analysis is performed on the attack event to determine the risk of the attack event, including: Obtain the attacker's attack path, attack methods, and attack sources, and based on the association between the attacker's attack path, attack methods, and attack sources and the knowledge graph, determine the remaining attack events related to this attack event in order to reconstruct the attack chain. The risk of this attack event is calculated based on the obtained attack chain using dynamic quantitative assessment and fuzzy comprehensive algorithm. Based on the scenario of this attack, a corresponding emergency response plan was developed to complete the maintenance of the attack response.
[0012] On the other hand, the present invention also provides an intelligent tracing system based on attack correlation analysis, the intelligent tracing system comprising: The network acquisition module is used to systematically collect network security-related information from multi-source heterogeneous data; The preprocessing module is used to preprocess the collected network security-related information. The knowledge graph construction module extracts entity relationships based on the preprocessed network security-related information to construct a knowledge graph. The knowledge graph optimization module is used to optimize the knowledge graph by setting up knowledge reasoning and optimization mechanisms to ensure that the knowledge graph can accurately reflect the complexity and dynamism of the cybersecurity field. The source tracing analysis module is used to obtain the attack source and perform correlation analysis between the attack source and the knowledge graph in order to reconstruct the path and locate the source. The risk determination module is used to perform security time correlation analysis on the attack source based on the correlation analysis between the attack source path and source point and the knowledge graph, so as to determine the risk of the attack source.
[0013] In another aspect, the present invention also provides a processor for running a program, wherein the program is executed to perform: an intelligent tracing method based on attack correlation analysis as described above.
[0014] Through the above technical solution, the present invention provides an intelligent tracing method, system, and processor based on attack correlation analysis. This method can systematically collect network security-related information from multi-source heterogeneous data, and then preprocess the collected information. After preprocessing, entity relationships can be extracted based on the preprocessed network security-related information, thereby constructing a knowledge graph. After constructing the knowledge graph, knowledge reasoning and optimization mechanisms can be set to optimize the knowledge graph, ensuring that it accurately reflects the complexity and dynamism of the network security field. After optimizing the knowledge graph, attack events can be obtained, and correlation analysis can be performed between the attack events and the knowledge graph, enabling path reconstruction and source location. Based on the correlation analysis between the attack source path and source point and the knowledge graph, security event correlation analysis can be performed on the attack event, thereby determining the risk of the attack event. This intelligent tracing method can automatically analyze attack events and quickly and accurately trace the source of attacks.
[0015] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0016] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of an intelligent attribution method based on attack correlation analysis according to an embodiment of the present invention; Figure 2 This is a flowchart of the preprocessing of an intelligent attribution method based on attack correlation analysis according to an embodiment of the present invention; Figure 3 This is a flowchart illustrating the construction of a knowledge graph using an intelligent attribution method based on attack correlation analysis, according to an embodiment of the present invention. Figure 4 This is a flowchart of a knowledge graph optimization method based on attack correlation analysis according to an embodiment of the present invention. Figure 5This is a flowchart of a source tracing method based on attack correlation analysis according to an embodiment of the present invention; Figure 6 This is a flowchart illustrating the risk determination of an intelligent attribution method based on attack correlation analysis according to an embodiment of the present invention. Detailed Implementation
[0017] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.
[0018] In the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, they do not mean that the applicant has used or necessarily used the solution.
[0019] Figure 1 This is a flowchart of an intelligent attribution method based on attack correlation analysis according to an embodiment of the present invention. In this invention, the intelligent attribution process may include: In step S1, network security-related information is systematically collected from multi-source heterogeneous data.
[0020] In step S2, the collected network security-related information is preprocessed.
[0021] In step S3, entity relationships are extracted based on the preprocessed network security-related information to construct a knowledge graph.
[0022] In step S4, a knowledge reasoning and optimization mechanism is set up to optimize the knowledge graph, ensuring that the knowledge graph can accurately reflect the complexity and dynamism of the cybersecurity field.
[0023] In step S5, attack events are acquired and correlated with the knowledge graph to perform path reconstruction and source location.
[0024] In step S6, based on the correlation analysis between the attack source path and source point and the knowledge graph, a security event correlation analysis is performed on the attack event to determine the risk of the attack event.
[0025] In this invention, during intelligent attribution, network security-related information can be systematically collected from multi-source heterogeneous data. This collected information can then be preprocessed. After preprocessing, entity relationships can be extracted based on the preprocessed network security-related information, thereby constructing a knowledge graph. Once the knowledge graph is constructed, it can be optimized by setting knowledge reasoning and optimization mechanisms to ensure it accurately reflects the complexity and dynamism of the network security field. After optimizing the knowledge graph, attack events can be acquired, and correlation analysis can be performed between these events and the knowledge graph to reconstruct paths and locate the source. Based on the correlation analysis between the attack source's path and source and the knowledge graph, security event correlation analysis can be performed on the attack event to determine its risk. This intelligent attribution method can automatically analyze attack events, enabling rapid and accurate attribution of attacks.
[0026] In one embodiment of the present invention, the network security related information may encompass vulnerability databases (such as CVE, CWE), attack technique libraries (such as MITRE ATT&CK, Exploit-DB), defense strategy sources (such as NVD, industry white papers), and open datasets (such as Kaggle). Data acquisition can comprehensively utilize web crawling techniques (using tools such as requests, aiohttp, BeautifulSoup, and Selenium to achieve high-concurrency requests and dynamic page parsing), standardized API calls (such as timed crawling of the official CVE API), and unstructured document parsing (combining PDFMiner and OCR technologies to extract text).
[0027] In one embodiment of the present invention, such as Figure 2 As shown, the preprocessing flow may include: In step S7, network security-related information is obtained, and meaningless tags in the network security-related information are removed by regular expressions, so that only plain text network security-related information is obtained.
[0028] In step S8, after obtaining the plain text network security-related information, the network security-related information is deduplicated and the field names and content are standardized using a hash algorithm.
[0029] In step S9, after normalization is completed, network security related information is segmented and stop words are removed.
[0030] In this invention, when preprocessing network security-related information, the relevant information can be obtained first. Then, meaningless tags can be removed from the information using regular expressions, resulting in only plain text information. After obtaining the plain text information, a hash algorithm can be used to deduplicate the information and normalize field names and content. After normalization, the information can be segmented into words and stop words can be removed, thus completing the preprocessing of the network security-related information.
[0031] In one embodiment of the present invention, such as Figure 3 As shown, the process of constructing a knowledge graph may include: In step S10, the preprocessed network security related information is obtained, and the start and end positions of the entities in the network security related information are found.
[0032] In step S11, the identified entities are assigned to corresponding predefined labels.
[0033] In step S12, network security-related information containing labeled entities is input into BERT, and the output is classified into relationships to determine the semantic relationship between any two entities in the sentence, thereby determining the triples in network security-related information.
[0034] In step S13, the triples are obtained, and the entities in the network security-related information are linked to the unique and correct entities in the knowledge base.
[0035] In step S14, the weight of the relationship between the two entities is determined by a trust assessment method.
[0036] In step S15, the triples with entity links and confirmed weights are stored in the graph database.
[0037] In step S16, a knowledge graph is constructed based on the triples in the graph database.
[0038] In this invention, when constructing a knowledge graph, preprocessed cybersecurity-related information can be obtained, and the start and end positions of entities within a sentence can be located, thereby identifying the relationships between the corresponding entities. After entity identification, the identified entities can be assigned to corresponding predefined labels, thus labeling the entities. After labeling, cybersecurity-related information containing the labeled entities can be input into BERT, and the output results can be classified to determine the semantic relationship between any two entities in the sentence, thereby identifying the triples in the cybersecurity-related information. After obtaining the triples, multiple complex entities in the cybersecurity-related information can be linked to a unique and correct entity in the knowledge base, thereby removing redundant entities from the triples. The weight of the relationship between two entities can be determined through a trust evaluation method, and then the triples with entity links and confirmed weights can be stored in the graph database. A knowledge graph can be constructed based on the triples in the graph database.
[0039] In one embodiment of the present invention, such as Figure 4 As shown, the knowledge graph optimization process may include: In step S17, knowledge graphs and cybersecurity-related information are obtained, and logical tasks are processed based on the OWL2 inference engine. Cypher queries and machine learning (such as neural networks) are used to mine potential relationships between entities.
[0040] In step S18, the knowledge graph is queried using a graph embedding algorithm to fill in the missing attributes in the knowledge graph and identify similar nodes in the knowledge graph.
[0041] In step S19, similar nodes and edges in the knowledge graph are merged.
[0042] In step S20, real-time knowledge injection is implemented through Kafka to continuously update the knowledge graph.
[0043] In this invention, during knowledge graph optimization, the knowledge graph and network security-related information can be acquired. Logical tasks can then be processed using an OWL2 inference engine, leveraging Cypher queries and machine learning (such as neural networks) to mine potential relationships between entities. When acquiring these relationships, some entities may be missing. Therefore, graph embedding algorithms can be used to query the knowledge graph, filling in missing attributes and entities and identifying similar nodes. After identifying similar nodes, they can be merged with edges, thus simplifying the knowledge graph. Real-time knowledge injection via Kafka allows for continuous updates to the knowledge graph.
[0044] In one embodiment of the present invention, such as Figure 5 As shown, the process of source tracing analysis may include: In step S21, the attack behavior and source IP are initially located through security device alarms, log and traffic analysis, server resource anomaly detection, honeypot system and email phishing real-time monitoring.
[0045] In step S22, based on the initial location of the attack behavior and source IP, a correlation query is performed in conjunction with the external threat situation, and the attacker's host and social information are obtained by combining JSONP traversal technology.
[0046] In step S23, based on the attacker's attack behavior, source IP and host, and social information, a complete attacker profile is constructed, covering network proxy, real identity, contact information, and organizational background.
[0047] In step S24, the attacker's attack path, attack methods, and attack sources are determined based on the correlation analysis between the attacker's profile and the knowledge graph.
[0048] In this invention, during source tracing analysis, attack behaviors and source IPs can be initially located through security device alarms, log and traffic analysis, server resource anomaly detection, honeypot systems, and real-time monitoring of phishing emails. Based on the initial location of attack behaviors and source IPs, correlation queries can be performed in conjunction with external threat information, and attacker host and social information can be obtained by combining JSONP traversal technology. Based on the attacker's attack behaviors, source IPs, hosts, and social information, a complete attacker profile can be constructed, covering network proxies, real identity, contact information, and organizational background. Based on the correlation analysis between this attacker profile and the knowledge graph, the attacker's attack path, attack methods, and attack source can be determined.
[0049] In one embodiment of the present invention, such as Figure 6 As shown, the risk identification process may include: In step S25, the attacker's attack path, attack method, and attack source are obtained, and based on the association between the attacker's attack path, attack method, and attack source and the knowledge graph, other attack events associated with this attack event are determined to reconstruct the attack chain.
[0050] In step S26, the risk of this attack event is calculated based on the obtained attack chain using dynamic quantitative evaluation and fuzzy synthesis algorithm.
[0051] In step S27, a corresponding emergency response plan is constructed based on the scenario of this attack event in order to complete the maintenance of the attack event.
[0052] In this invention, during risk assessment, the attacker's attack path, attack methods, and attack sources can be obtained. Furthermore, based on the associations between the attacker's attack path, attack methods, and attack sources within a knowledge graph, other attack events related to the current attack can be identified, thereby reconstructing the attack chain. The risk of this attack event can be calculated using dynamic quantitative evaluation and fuzzy comprehensive algorithms based on the obtained attack chain. According to the scenario of this attack event, a corresponding emergency response plan can be constructed, thereby enabling the maintenance of the attack response.
[0053] On the other hand, the present invention can also provide an intelligent tracing system based on attack correlation analysis. This intelligent tracing system may include: a network acquisition module, a preprocessing module, a knowledge graph construction module, a knowledge graph optimization module, a tracing analysis module, and a risk determination module. The network acquisition module can be used to systematically collect network security-related information from multi-source heterogeneous data. The preprocessing module can be used to preprocess the collected network security-related information. The knowledge graph construction module can extract entity relationships based on the preprocessed network security-related information to construct a knowledge graph. The knowledge graph optimization module can be used to optimize the knowledge graph by setting knowledge reasoning and optimization mechanisms to ensure that the knowledge graph accurately reflects the complexity and dynamism of the network security field. The tracing analysis module can be used to obtain the attack source and perform correlation analysis between the attack source and the knowledge graph to reconstruct the path and locate the source. The risk determination module can be used to perform security time correlation analysis on the attack source based on the correlation analysis between the attack source's path and source and the knowledge graph to determine the risk of the attack source.
[0054] In another aspect, the present invention may also provide a processor for running a program, wherein the program is executed to perform: an intelligent tracing method based on attack correlation analysis as described above.
[0055] Through the above technical solution, the present invention provides an intelligent tracing method, system, and processor based on attack correlation analysis. This method can systematically collect network security-related information from multi-source heterogeneous data, and then preprocess the collected information. After preprocessing, entity relationships can be extracted based on the preprocessed network security-related information, thereby constructing a knowledge graph. After constructing the knowledge graph, knowledge reasoning and optimization mechanisms can be set to optimize the knowledge graph, ensuring that it accurately reflects the complexity and dynamism of the network security field. After optimizing the knowledge graph, attack events can be obtained, and correlation analysis can be performed between the attack events and the knowledge graph, enabling path reconstruction and source location. Based on the correlation analysis between the attack source path and source point and the knowledge graph, security event correlation analysis can be performed on the attack event, thereby determining the risk of the attack event. This intelligent tracing method can automatically analyze attack events and quickly and accurately trace the source of attacks.
[0056] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0057] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0058] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0059] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0060] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0061] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0062] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0063] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0064] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. An intelligent attribution tracing method based on attack correlation analysis, characterized in that, The intelligent traceability method includes: Systematically collect cybersecurity-related information from multi-source heterogeneous data; The collected network security-related information is preprocessed; Entity relationships are extracted based on the preprocessed network security-related information to construct a knowledge graph; By setting up knowledge reasoning and optimization mechanisms, the knowledge graph is optimized to ensure that it can accurately reflect the complexity and dynamism of the cybersecurity field. The attack events are acquired and correlated with the knowledge graph to perform path reconstruction and source point localization. Based on the correlation analysis between the attack source path and origin and the knowledge graph, a security event correlation analysis is performed on the attack event to determine the risk of the attack event.
2. The intelligent traceability method according to claim 1, characterized in that, The cybersecurity-related information includes: vulnerability databases, attack databases, and open datasets.
3. The intelligent traceability method according to claim 1, characterized in that, The collected network security-related information is preprocessed, including: The network security-related information is obtained, and meaningless tags in the network security-related information are removed by regular expressions, so that only the plain text of the network security-related information is obtained. After obtaining the plain text information related to network security, the network security information is deduplicated and the field names and content are standardized using a hash algorithm. After standardization, the network security-related information is segmented and stop words are removed.
4. The intelligent traceability method according to claim 1, characterized in that, Based on the preprocessed network security-related information, entity relationships are extracted to construct a knowledge graph, including: Obtain the preprocessed network security-related information and locate the start and end positions of the entities in the network security-related information. The identified entities are assigned to corresponding predefined labels; The network security-related information, which includes the labeled entities, is input into BERT, and the output is classified into relationships to determine the semantic relationship between any two entities in the sentence, thereby determining the triples in the network security-related information. Obtain the triplet and link the entity in the network security-related information to the unique and correct entity in the knowledge base; The weight of the relationship between two entities is determined by a trust assessment method; Store the triples with entity links and confirmed weights in the graph database; A knowledge graph is constructed based on the triples in the graph database.
5. The intelligent traceability method according to claim 4, characterized in that, By setting up knowledge reasoning and optimization mechanisms, the knowledge graph is optimized to ensure that it accurately reflects the complexity and dynamism of the cybersecurity field, including: The knowledge graph and network security-related information are obtained, and logical tasks are processed based on the OWL2 inference engine. The potential relationships between entities are mined by relying on Cypher query and machine learning (such as neural networks). The knowledge graph is queried using a graph embedding algorithm to fill in missing attributes and identify similar nodes in the knowledge graph. Merge similar nodes and edges in the knowledge graph; Real-time knowledge injection is achieved through Kafka to continuously update the knowledge graph.
6. The intelligent traceability method according to claim 1, characterized in that, Acquire attack events and perform correlation analysis between the attack events and the knowledge graph to reconstruct paths and locate source points, including: By using security device alarms, log and traffic analysis, server resource anomaly detection, and real-time monitoring of honeypot systems and email phishing, the attack behavior and source IP can be initially located. Based on the initial identification of the attack behavior and source IP, we conducted correlation queries with external threat information and used JSONP traversal technology to obtain the attacker's host and social information. Based on the attacker's attack behavior, source IP and host, and social information, construct a complete attacker profile that includes network proxy, real identity, contact information, and organizational background; Based on the correlation analysis between the attacker profile and the knowledge graph, the attacker's attack path, attack methods, and attack sources are determined.
7. The intelligent traceability method according to claim 1, characterized in that, Based on the correlation analysis between the attack source path and origin and the knowledge graph, a security event correlation analysis is performed on the attack event to determine the risk of the attack event, including: Obtain the attacker's attack path, attack methods, and attack sources, and based on the association between the attacker's attack path, attack methods, and attack sources and the knowledge graph, determine the remaining attack events related to this attack event in order to reconstruct the attack chain. The risk of this attack event is calculated based on the obtained attack chain using dynamic quantitative assessment and fuzzy comprehensive algorithm. Based on the scenario of this attack, a corresponding emergency response plan was developed to complete the maintenance of the attack response.
8. An intelligent attribution tracing system based on attack correlation analysis, characterized in that, The intelligent traceability system includes: The network acquisition module is used to systematically collect network security-related information from multi-source heterogeneous data; The preprocessing module is used to preprocess the collected network security-related information. The knowledge graph construction module extracts entity relationships based on the preprocessed network security-related information to construct a knowledge graph. The knowledge graph optimization module is used to optimize the knowledge graph by setting up knowledge reasoning and optimization mechanisms to ensure that the knowledge graph can accurately reflect the complexity and dynamism of the cybersecurity field. The source tracing analysis module is used to obtain the attack source and perform correlation analysis between the attack source and the knowledge graph in order to reconstruct the path and locate the source. The risk determination module is used to perform security time correlation analysis on the attack source based on the correlation analysis between the attack source path and source point and the knowledge graph, so as to determine the risk of the attack source.
9. A processor, characterized in that, Used to run a program, wherein the program is run to execute: an intelligent tracing method based on attack correlation analysis as described in any one of claims 1-7.
Citation Information
Patent Citations
Security event association method and system based on network security knowledge graph, and medium
CN111177417A
Network attack early warning and tracing method, system and device based on affair knowledge graph
CN118869373A
Industrial control intrusion detection method and system based on ATTCK framework
CN119449475A
Power production data private network security situation awareness system and method
CN120110735A
AI agent autonomous defense system and method for network attack path prediction
CN120546952A