Traceability analysis method and device for APT attack detection, equipment and medium

By generating an adjacency matrix of attack scenarios and causal inference, a dynamically evolving attack target network is constructed, which solves the problems of easily bypassed detection methods and poor source tracing analysis in APT attack detection, and achieves efficient and accurate detection and prediction of complex APT attacks.

CN121508992APending Publication Date: 2026-02-10CHINA MOBILE GROUP DESIGN INST +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511718623.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-21
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing technologies for APT attack detection suffer from problems such as easy bypassing of detection methods, impact on system stability, and significant latency, resulting in poor effectiveness of source tracing analysis.

Method used

By acquiring alarm logs from the intrusion detection system, an adjacency matrix of attack scenarios is generated, the causal relationship between different attack behaviors is identified, a multi-step attack relationship graph is constructed, and multi-step attack alarm sequences are extracted and attack target networks are generated, ultimately predicting the attack intent.

Benefits of technology

It significantly improves the detection depth and prediction accuracy of complex APT attacks, realizing the transformation from passive alerts to proactive threat identification, and can accurately characterize the attacker's intent and multi-step attack path.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508992A_ABST
    Figure CN121508992A_ABST
Patent Text Reader

Abstract

The invention provides a traceability analysis method and device for APT attack detection, equipment and a medium, and the method comprises the steps: obtaining an alarm log of an intrusion detection system, and generating an attack scene adjacency matrix based on the alarm log; identifying a causal relationship between different attack behaviors based on the attack scene adjacency matrix to generate a multi-step attack relationship graph; extracting a multi-step attack alarm sequence according to the multi-step attack relation graph; generating an attack target network according to the multi-step attack alarm sequence; and performing attack intention prediction according to the attack target network. Therefore, the attack scene graph is generated by associating isolated alarms, the key attack sequence is extracted by using causal inference, and the dynamically evolved attack target network is constructed, so that the intention of an attacker and a multi-step attack path can be accurately described, and the detection depth and prediction accuracy of a complex APT attack are remarkably improved; and conversion from passive alarm to active threat identification is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security technology, specifically to a method, apparatus, device, and medium for tracing and analyzing the source of APT attacks. Background Technology

[0002] With the development of internet information technology, the network environment is becoming increasingly complex, and internal and external security risks and threats are also increasing. In recent years, complex multi-step cyberattacks have become increasingly prominent in modern cyberspace; these attacks are known as Advanced Persistent Threats (APTs). Compared with traditional attack patterns, APTs are characterized by long duration, complex attack chains, high stealth, diverse attack methods, and extremely high harm. They can be launched through various means, including social engineering, zero-day vulnerabilities, and infected storage media.

[0003] In APT attack detection, single-point intrusion detection schemes are commonly used, such as network traffic analysis, static software signature detection, dynamic sandbox detection, and hook techniques. However, this approach suffers from drawbacks such as ease of bypassing, impact on system stability, and significant latency, resulting in poor effectiveness for tracing and analyzing the source of APT attacks. Summary of the Invention

[0004] This disclosure aims to at least partially address one of the technical problems in the related art.

[0005] Therefore, the purpose of this disclosure is to propose a source tracing analysis method, device, electronic device and storage medium for APT attack detection. By generating an attack scenario graph by associating isolated alarms and extracting key attack sequences using causal inference, a dynamically evolving attack target network is constructed. This enables accurate characterization of attacker intent and multi-step attack paths, significantly improving the detection depth and prediction accuracy of complex APT attacks, and realizing the transformation from passive alarm to proactive threat identification.

[0006] To achieve the above objectives, the source tracing analysis method for APT attack detection proposed in the first aspect of this disclosure includes: Obtain alarm logs from the intrusion detection system and generate an adjacency matrix of attack scenarios based on the alarm logs; Based on the adjacency matrix of the attack scenario, the causal relationship between different attack behaviors is identified to generate a multi-step attack relationship graph; Based on the multi-step attack relationship diagram, multi-step attack alarm sequence extraction is performed; Based on the multi-step attack alert sequence, generate the target network for the attack. Based on the target network, attack intent is predicted.

[0007] To achieve the above objectives, the APT attack detection tracing and analysis apparatus proposed in the second aspect of this disclosure includes: The acquisition module is used to acquire alarm logs from the intrusion detection system and generate an attack scenario adjacency matrix based on the alarm logs. The first generation module is used to identify the causal relationship between different attack behaviors based on the adjacency matrix of the attack scenario, so as to generate a multi-step attack relationship graph. The processing module is used to extract multi-step attack alarm sequences based on the multi-step attack relationship graph. The second generation module is used to generate the attack target network based on the multi-step attack alarm sequence; The prediction module is used to predict the attack intent based on the target network.

[0008] The electronic device proposed in the third aspect of this disclosure includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the source tracing analysis method for APT attack detection as proposed in the first aspect of this disclosure.

[0009] The fourth aspect of this disclosure provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the source tracing analysis method for APT attack detection as proposed in the first aspect of this disclosure.

[0010] The fifth aspect of this disclosure provides a computer program product in which, when the instructions in the computer program product are executed by a processor, the source tracing analysis method for APT attack detection as proposed in the first aspect of this disclosure is performed.

[0011] The APT attack detection tracing and analysis method, apparatus, electronic device, and storage medium disclosed herein acquire alarm logs from an intrusion detection system and generate an attack scenario adjacency matrix based on the alarm logs. Based on the attack scenario adjacency matrix, causal relationships between different attack behaviors are identified to generate a multi-step attack relationship graph. Multi-step attack alarm sequences are extracted from the multi-step attack relationship graph. An attack target network is generated based on the multi-step attack alarm sequences. Attack intent is predicted based on the attack target network. Thus, by associating isolated alarms to generate an attack scenario graph and extracting key attack sequences using causal inference, a dynamically evolving attack target network is constructed. This allows for accurate characterization of attacker intent and multi-step attack paths, significantly improving the detection depth and prediction accuracy of complex APT attacks, and realizing a shift from passive alarm to proactive threat identification.

[0012] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this disclosure. Attached Figure Description

[0013] The above and / or additional aspects and advantages of this disclosure will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which: Figure 1 This is a flowchart illustrating the source tracing analysis method for APT attack detection proposed in one embodiment of this disclosure; Figure 2 This is a flowchart illustrating the source tracing analysis method for APT attack detection proposed in another embodiment of this disclosure; Figure 3 It is based on the device node topology diagram presented in this disclosure; Figure 4 This is a flowchart for predicting attack intent based on the information presented in this disclosure; Figure 5 This is a schematic diagram of the structure of an APT attack detection tracing and analysis device proposed in an embodiment of this disclosure; Figure 6 This is a block diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0014] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are used only to explain this disclosure, and should not be construed as limiting this disclosure. Rather, embodiments of this disclosure include all variations, modifications, and equivalents falling within the spirit and scope of the appended claims.

[0015] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this disclosure are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0016] Figure 1 This is a flowchart illustrating the source tracing analysis method for APT attack detection proposed in one embodiment of this disclosure.

[0017] It should be noted that the execution subject of the APT attack detection source analysis method in this embodiment is the APT attack detection source analysis device. This device can be implemented by software and / or hardware. This device can be configured in an electronic device, which may include, but is not limited to, a terminal, a server, etc. For example, the terminal may be a mobile phone, a PDA, etc.

[0018] like Figure 1 As shown, the source tracing and analysis method for detecting this APT attack includes: S101: Obtain alarm logs from the intrusion detection system and generate an adjacency matrix of attack scenarios based on the alarm logs.

[0019] An intrusion detection system can refer to a system that continuously monitors network traffic or system activity in order to detect unauthorized access, malicious behavior, or violations of security policies.

[0020] The alarm log refers to the system logs generated by the intrusion detection system due to APT attack detection.

[0021] The adjacency matrix of the attack scenario can be a two-dimensional square matrix (usually an N*N matrix, where N is the number of attack behavior nodes). It uses 0 and 1 (or weight values) to quantitatively describe the connection relationship between each node (attack behavior) in the attack scenario graph.

[0022] In this embodiment of the disclosure, when generating the adjacency matrix of the attack scenario based on the alarm log, it can be based on a pre-trained machine learning model, or it can be based on a method combining numbers and shapes to generate the adjacency matrix of the attack scenario based on the alarm log, and there is no limitation on this.

[0023] Optionally, in some embodiments, when generating the attack scenario adjacency matrix based on alarm logs, the alarm logs can be converted into a preset tuple format data, and the tuple format data can be converted into alarm vectors through word embedding. The tuple format data includes source IP, destination IP, source port, destination port, protocol, timestamp, attack type, and related data on behavioral characteristics. An attention-based encoder-decoder model is used to process the alarm vectors to generate an attack scenario adjacency matrix representing the relationships between attack behaviors. The attention-based encoder-decoder model uses an autoencoder to reduce the dimensionality of the behavioral features and extract features. This allows for the extraction and vectorization of key information from the alarm logs, and the use of an attention-based encoder-decoder model to process the alarm vectors, thereby effectively improving the indicative effect of the obtained attack scenario adjacency matrix.

[0024] Among them, tuple format data refers to a data format in which a complex piece of information is broken down into multiple fixed parts and arranged in a preset order.

[0025] In this embodiment of the disclosure, the specific data content contained in the tuple format data can be flexibly adjusted according to the application scenario, and there are no restrictions on this.

[0026] In the attention-based encoder-decoder model, the encoder outputs a vector representation of each alarm, and the decoder establishes the relationship between the encoder outputs.

[0027] In this embodiment of the disclosure, when acquiring alarm logs from the intrusion detection system and generating an adjacency matrix of attack scenarios based on the alarm logs, the massive, disordered raw alarms can be intelligently aggregated into an adjacency matrix that represents the relationships between attack behaviors. This elevates security analysis from processing isolated alarms to understanding the overall attack scenario. The generated adjacency matrix accurately describes the potential causal relationships between attack behaviors, providing a high-quality, computable, and structured data foundation for subsequent causal discovery algorithms based on reinforcement learning. This matrix is ​​the direct basis for constructing multi-step attack relationship graphs and extracting attack paths, enabling the system to examine the entire attack from a macro perspective and providing key support for ultimately achieving accurate attack intent prediction.

[0028] S102: Identify the causal relationships between different attack behaviors based on the adjacency matrix of the attack scenario to generate a multi-step attack relationship graph.

[0029] Among them, causal relationship can refer to the logical relationship between different attack behaviors.

[0030] Among them, the multi-step attack relationship graph can be a directed graph that accurately describes the logical order and causal relationship between different attack stages (steps) in a complete network attack in a visual way.

[0031] Optionally, in some embodiments, when identifying the causal relationships between different attack behaviors based on the adjacency matrix of the attack scenario to generate a multi-step attack relationship graph, an acyclic graph set can be generated by traversing the adjacency matrix of the attack scenario. This acyclic graph set is then used as training data, and an actor-critic algorithm is employed for reinforcement learning. The acyclic graph with the best reward score is then output as the multi-step attack relationship graph. This achieves an intelligent leap from correlation to causal discovery in attack scenarios, automatically and reliably identifying the most authentic attack causal chain through a data-driven approach.

[0032] In this embodiment, by traversing and filtering the set of acyclic graphs, the logical fallacy of causal loops is fundamentally eliminated, ensuring that the generated attack path evolves unidirectionally and conforms to the development pattern of attack events in the real world. An actor-critic algorithm is introduced for reinforcement learning, using the Bayesian Information Criterion (BIC) score as the core part of the reward function. This allows the system to quantitatively evaluate the explanatory power and simplicity of each candidate causal graph, and efficiently finds the optimal causal structure from a huge search space through a mechanism combining intelligent exploration (actors) and value judgment (criticism). The final output acyclic graph with the best reward score is not only an attack relationship graph, but also a causal model verified by rigorous mathematical standards. This provides security analysts with clear and credible root cause analysis and attack path visualization of attack activities, greatly improving the accuracy and operability of APT attack tracing analysis.

[0033] S103: Extract multi-step attack alarm sequences based on the multi-step attack relationship diagram.

[0034] Among them, a multi-step attack alarm sequence can refer to a logical and time-sequential main attack chain extracted from massive and chaotic raw alarms.

[0035] In other words, in this embodiment of the disclosure, one or more representative linear attack paths can be identified and extracted from graph structure data characterizing a global attack scenario. Wherein: Input: A complex graph that may contain multiple branches, merging points, and many minor or probing attacks.

[0036] Output: A clear main attack chain, for example: [Attack Action A] -> [Attack Action B] -> [Attack Action C] -> ... In this embodiment of the disclosure, when multi-step attack alarm sequence extraction is performed based on the multi-step attack relationship graph, the transformation from global association to main path focus can be realized, and the complex mesh attack scenario can be refined into a clear and linear attack storyline, providing directly processable input for accurate intent prediction.

[0037] S104: Generate the target network for attack based on the multi-step attack alarm sequence.

[0038] Among them, the attack target network can visualize the attack path, making the abstract attack steps concrete and visible. Security analysts can see the source of the attack, its current location, and its direction of attack at a glance.

[0039] In this embodiment of the disclosure, when generating the target network for an attack based on a multi-step attack alarm sequence, the abstract and logical attack steps can be mapped to the real and physical network world, providing a realistic basis for predicting attack intentions.

[0040] S105: Predict attack intent based on the target network.

[0041] In this embodiment of the disclosure, when predicting attack intent based on the target network, it can be based on a third-party device, or it can be based on a combination of numerical and graphical methods to predict attack intent based on the target network, without any limitation.

[0042] Optionally, in some embodiments, when predicting attack intent based on the target network, the target network can be processed using a link prediction method based on a preset link prediction function to predict the attack intent. This transforms the abstract security problem of attack intent prediction into a precise and computable graph network link prediction problem, thereby enabling the quantification and probabilistic inference of the attacker's next target.

[0043] Optionally, in some embodiments, when predicting attack intent based on the target network, attacker features can be extracted from the target network using a graph neural network, and spatiotemporal features of the target network can be extracted using a spatiotemporal convolutional network. The attacker features and spatiotemporal features are then combined to predict the attack intent. This achieves multi-dimensional, deep, and dynamic perception and modeling of attacker behavior, enabling the prediction of their final intent and next target with unprecedented accuracy and contextual understanding.

[0044] In this embodiment, alarm logs from the intrusion detection system are acquired, and an attack scenario adjacency matrix is ​​generated based on these logs. The causal relationships between different attack behaviors are identified using this adjacency matrix to generate a multi-step attack relationship graph. Multi-step attack alarm sequences are extracted from the multi-step attack relationship graph. An attack target network is generated based on these multi-step attack alarm sequences. Finally, attack intent is predicted based on the attack target network. Thus, by associating isolated alarms to generate an attack scenario graph and extracting key attack sequences using causal inference, a dynamically evolving attack target network is constructed. This allows for accurate characterization of attacker intent and multi-step attack paths, significantly improving the detection depth and prediction accuracy of complex APT attacks, and achieving a shift from passive alarms to proactive threat identification.

[0045] Figure 2 This is a flowchart illustrating the source tracing analysis method for APT attack detection proposed in another embodiment of this disclosure.

[0046] like Figure 2 As shown, the source tracing and analysis method for detecting this APT attack includes: S201: Obtain the alarm logs of the intrusion detection system and generate an adjacency matrix of attack scenarios based on the alarm logs.

[0047] S202: Identify the causal relationships between different attack behaviors based on the adjacency matrix of the attack scenario to generate a multi-step attack relationship graph.

[0048] For a detailed description of S201 and S202, please refer to the above embodiments, which will not be repeated here.

[0049] S203: Determine the node attributes in the multi-step attack relationship graph, where the node attributes include timestamps and node importance weights.

[0050] In this embodiment of the disclosure, by assigning a timestamp attribute to each node, subsequent sequence extraction algorithms (such as time-based DFS) can strictly follow the true chronological order of events during traversal. This effectively prevents causal reversal, ensures that the final extracted attack path is logically sound in terms of time, and avoids erroneous reasoning caused by temporal disorder.

[0051] In this embodiment, by assigning importance weights to nodes (e.g., based on the functional role and business value of the attacked device), the algorithm can intelligently identify and prioritize the main attack path where the attacker's true intent lies from complex, multi-branch attack graphs. This allows the analysis to focus on the paths that pose the greatest threat to business and are of most interest to the attacker, filtering out a large number of secondary and deceptive attack behaviors, greatly improving the efficiency and accuracy of the analysis. The introduction of node importance weights essentially deeply integrates the physical topology of the network (device connection relationships) with the enterprise's business logic (device importance). This makes the constructed attack scenario no longer a purely technical connection graph, but a threat model carrying business risk information, providing direct support for security assessment and decision-making from a business impact perspective.

[0052] In this embodiment of the disclosure, when the node attributes in the multi-step attack relationship graph are determined, including timestamps and node importance weights, a quantifiable decision basis with physical meaning and business semantics can be provided for subsequent intelligent analysis algorithms, upgrading the original graph structure data into a semantic knowledge graph rich in contextual information.

[0053] S204: Based on timestamps and node importance weights, a depth-first search algorithm is executed to extract a multi-step attack alarm sequence from the multi-step attack relationship graph. The search path selection strategy of the depth-first search algorithm is constrained by both time order and node importance weights.

[0054] In this embodiment of the disclosure, when the search path selection strategy of the depth-first search algorithm is simultaneously constrained by time order and node importance weight, it can ensure that the extracted attack sequence has both temporal authenticity, causal logic and business relevance, thereby accurately reconstructing the attacker's main attack intent.

[0055] In other words, after obtaining the multi-step attack relationship graph in this embodiment, the node attributes in the multi-step attack relationship graph can be determined. These node attributes include timestamps and node importance weights. Based on the timestamps and node importance weights, a depth-first search algorithm is executed to extract a multi-step attack alarm sequence from the multi-step attack relationship graph. The search path selection strategy of the depth-first search algorithm is constrained by both time order and node importance weights. Therefore, by introducing dual constraints of time order and weights, the traditional graph traversal algorithm is transformed into an intelligent path discovery engine with business cognitive capabilities, thereby automatically and accurately extracting the most threatening and realistic main attack chain from complex attack scenarios.

[0056] S205: Obtain the topology information of the system network.

[0057] Topology information refers to data that describes the physical or logical connections between elements (nodes) in a network, defining the potential paths for data to flow through the network.

[0058] In this embodiment of the disclosure, when the topology information of the system network is obtained, the actual connection relationship of the devices can be provided for the subsequent construction of the network of the attack target.

[0059] S206: Map each alarm event in the multi-step attack alarm sequence to the corresponding system device to create a system device node.

[0060] Among them, system device nodes can refer to nodes used to indicate the system devices corresponding to alarm events.

[0061] In this embodiment of the disclosure, when each alarm event in a multi-step attack alarm sequence is mapped to a corresponding system device to create a system device node, abstract, logical attack activities can be anchored to specific, physical network assets, thereby transforming network security threats from a technical problem into a clear asset risk management problem.

[0062] S207: Create an attacker node based on the source IP information of the alarm event.

[0063] In this context, the attacker node represents the source or control center that initiates malicious activities throughout the multi-step attack process.

[0064] In this embodiment of the disclosure, when an attacker node is created based on the source IP information of an alarm event, discrete attack behaviors can be uniformly attributed to a stable entity, thereby constructing a clear attack source perspective in a complex attack scenario and laying the foundation for understanding global attack intentions and coordinated actions.

[0065] S208: Based on topology information, connect the edges between the attacker node and the system device node, as well as the edges between different system device nodes, to obtain the target network.

[0066] In the process of constructing the target network, the multi-step attack alarm sequence provides the logical steps and order of the attack, and the system network topology provides the actual connection relationship of the devices.

[0067] In other words, in this embodiment, after obtaining the multi-step attack alarm sequence, the topology information of the system network can be acquired; each alarm event in the multi-step attack alarm sequence is mapped to a corresponding system device to create a system device node; an attacker node is created based on the source IP information of the alarm event; and edges between the attacker node and the system device node, as well as edges between different system device nodes, are connected based on the topology information to obtain the target network. Thus, by mapping the alarm sequence to system device nodes and creating attacker nodes based on source IPs, this step solidifies each step in the attack chain into an adversarial relationship between the attacker and defender's specific assets, providing a physical object for understanding and quantifying risk. Introducing topology information as the basis for connecting edges prevents logical reasoning from becoming detached from reality. It ensures that in the target network, two connected device nodes are actually reachable in the real network. This effectively filters out false attack paths that are logically possible but physically infeasible, greatly improving the accuracy and credibility of the model and preventing security teams from deploying defenses in the wrong direction. The resulting attack target network is a composite data volume containing heterogeneous nodes (attackers / devices), temporally ordered edges, and real network connectivity. This structured network graph is a perfect input for subsequent applications of Graph Neural Networks (GNNs) and Spatiotemporal Convolutional Networks (ST-GCNs) for deep feature extraction and intent prediction. It simultaneously captures the spatial diffusion patterns and temporal evolution of the attack.

[0068] S209: Predict attack intent based on the target network.

[0069] For a detailed description of S209, please refer to the above embodiments, which will not be repeated here.

[0070] In this embodiment, node attributes in the multi-step attack relationship graph are determined, including timestamps and node importance weights. A depth-first search algorithm is executed based on these timestamps and importance weights to extract a multi-step attack alarm sequence from the graph. The path selection strategy of the depth-first search algorithm is constrained by both time order and node importance weights. Thus, by introducing dual constraints of time order and weights, the traditional graph traversal algorithm is transformed into an intelligent path discovery engine with business awareness capabilities, automatically and accurately extracting the most threatening and realistic main attack chain from complex attack scenarios. The process involves acquiring the system network topology information; mapping each alarm event in the multi-step attack alarm sequence to a corresponding system device to create a system device node; creating an attacker node based on the source IP information of the alarm event; and connecting edges between the attacker node and system device nodes, as well as edges between different system device nodes, based on the topology information to obtain the target network. Therefore, by mapping alarm sequences to system device nodes and creating attacker nodes based on source IPs, this step solidifies each step in the attack chain into an adversarial relationship between specific assets of the attacker and defender, providing a tangible object for understanding and quantifying risk. Introducing topological information as the basis for connecting edges prevents logical reasoning from becoming unrealistic. It ensures that two connected device nodes in the target network are actually reachable in the real network. This effectively filters out false attack paths that are logically possible but physically infeasible, greatly improving the accuracy and credibility of the model and preventing security teams from deploying defenses in the wrong direction. The final generated target network is a composite data body containing heterogeneous nodes (attackers / devices), temporally ordered edges, and real network connectivity. This structured network graph is a perfect input for subsequent applications of Graph Neural Networks (GNNs) and Spatiotemporal Convolutional Networks (ST-GCNs) for deep feature extraction and intent prediction. It simultaneously captures the spatial diffusion pattern and temporal evolution of the attack.

[0071] Based on the above embodiments, this application proposes a source tracing and analysis method and system for APT attack detection, which can be applied to local area network or industrial internet scenarios where multiple types of devices exist and are connected by networks, such as... Figure 3 As shown, Figure 3 Based on the device node topology diagram presented in this disclosure, an attacker can gain control of one of the device nodes and launch attacks on other node devices from that device node. In a typical local area network or industrial internet environment, this may include the following elements: Various types of equipment: such as servers, workstations, routers, switches, industrial control systems (ICS), sensors, etc.

[0072] Network connectivity: Devices are connected via wired or wireless networks, forming a complex network topology.

[0073] Attackers: Attackers may use social engineering, zero-day vulnerabilities, phishing attacks, and other techniques to first gain control of one or more device nodes in the network.

[0074] Attack behavior: Once an attacker gains control of a node, they may further use that node as a springboard to launch broader attacks on other devices in the network, such as data theft, service interruption, and system control.

[0075] Based on the above application scenarios, this application proposes a source tracing and analysis method and system for APT attack detection, such as... Figure 4 As shown, Figure 4 This is a flowchart for predicting attack intent based on the present disclosure, wherein the specific steps include: Step 401, Log Data Processing: In this step, the log data mainly consists of alarm logs obtained by the intrusion detection system. These alarm logs are then converted into a 7-tuple format, which includes: (source IP, destination IP, source port, destination port, protocol, timestamp, attack type, behavioral characteristics). This 7-tuple data is then transformed into a vector form through word embedding, for example, using Global Vectors for Word Representation (GloVe). The advantage of using GloVe in this example is that, unlike Word2vec, GloVe not only relies on local statistical information (the local context of words) but also combines global statistical information (word co-occurrence) to obtain word vectors, where x = GloVe(alarm log). An example of the alarm log information is shown in Table 1. Table 1

[0076] Among them, the behavioral feature column is a label for behavioral features, which corresponds to the functional output of different intrusion detection devices, matching the attack feature library in each type of device, or user-defined behavioral feature labels.

[0077] Step 402: Generate the adjacency matrix A for the attack scenario: Specifically, an attention-based encoder-decoder model is used to generate a graph adjacency matrix. The encoder outputs a vector representation of each alarm, and the decoder establishes the relationships between the encoder outputs. An autoencoder is used to perform dimensionality reduction and feature extraction on behavioral features. The autoencoder consists of an encoder and a decoder. The encoder maps the input data to a latent space, and the decoder reconstructs the data from the latent space back to the original input. Based on the behavioral features in the log data, an attack scenario graph is constructed, where nodes represent different attack behaviors and edges represent the causal relationships between these behaviors. The encoder employs a Transformer structure with a multi-head attention mechanism, containing multiple Transformer blocks, each containing a multi-head attention network and a feedforward network. For the embedded representation of each vector in the input sequence X, the query, key, and value matrices are calculated respectively.

[0078] in, The weight matrices correspond to the query, key, and value, respectively.

[0079] Calculate the multi-head attention representation ei as the encoder output:

[0080] For multi-head attention mechanisms, multiple heads are defined:

[0081] in, In multi-head attention mechanisms, the outputs of multiple attention heads are concatenated and then subjected to a linear transformation to obtain the final output. The matrix involved is used as the weight matrix for this linear transformation. The output of each attention output after passing through the feedforward neural network is:

[0082] Where x is the input vector, This is the first linear transformation weight matrix. Here, is the bias vector for the first linear transformation, and is the ReLU activation function, which performs a nonlinear mapping on the result of the linear transformation. This is the second linear transformation weight matrix. The second linear transformation bias vector, through these two linear transformations and the ReLU activation function, allows the feedforward neural network to capture and process the complex features of the input vector.

[0083] The decoder establishes the relationships between the encoder outputs, generating an adjacency matrix A of the graph, where each element... The calculation is as follows:

[0084] and It is a trainable weight matrix (based on the training of the autoencoder, the model parameters are iteratively updated through the encoder loss function. This training step is a regular training of the autoencoder and will not be elaborated here). The trainable parameter vector in the decoder is used for weighting. This is the activation function, used to map the result of the linear transformation to a suitable range, typically [-1, 1].

[0085] Step 403: Based on the generated adjacency matrix A, identify causal relationships to generate edge attributes and multi-step attack relationship graphs for each node in the adjacency matrix. : Specifically, reinforcement learning is applied to causal inference to determine the causal relationships between nodes in the graph. A reward function is designed, considering the Bayesian Information Criterion (BIC) score and acyclic constraints. This includes: Step 403-1: Causal inference based on RL, from the multi-step attack relationship graph The Bayesian Information Criterion (BIC) scores for directed graphs, which identify causal relationships with the best scores, are as follows:

[0086] in, Given a multi-step attack relationship graph and parameters Under the conditions, The probability of this is typically calculated through the model's ability to fit the data. The number of model parameters is usually determined during the model design phase, and m is the total number of alarm events in the training data. The parameters are obtained through the training process, usually by maximizing the likelihood function of the data or minimizing the loss function. The adjacency matrix is ​​required to be an acyclic graph, which is obtained by a traversal algorithm. Step 403-2: Based on the generated adjacency matrix A, traverse and generate a set of acyclic graphs; Algorithms for traversing acyclic graphs include ( Initialization: Set an adjacency matrix A, where A[i][j] indicates whether there is an edge between vertex i and vertex j. Initialize a boolean array visited to mark whether each vertex has been visited.

[0087] Choose a starting point: Select a vertex from the adjacency matrix as the starting point. Usually, you can choose any unvisited vertex.

[0088] Depth-First Search (DFS): Starting from the starting point, perform a depth-first search, recursively visiting all unvisited adjacent vertices. During the visit, record the vertices and edges along the visited path, forming a subgraph.

[0089] Checking for cycles: During Depth-First Search (DFS), if a vertex that has already been visited is not the parent node of the current vertex, it indicates the existence of a cycle, and the search needs to be restarted. Generating acyclic subgraphs: Repeat steps 3 and 4 until all vertices have been visited, or an acyclic subgraph is found. Output: The vertices and edges of the generated acyclic subgraph. Step 403-3: The set of acyclic graphs generated by the root traversal is used as training data, and the actor-critic algorithm is used for reinforcement learning; The reward score for BIC is calculated based on the acyclic graph conveniently generated in the above steps.

[0090] Typically, selections are made based on needs during the model design phase, and may be adjusted based on experience and experimentation. By checking the diagram The calculation is based on whether the graph contains cycles. If the graph contains cycles, then... It is 1 if it is 1, otherwise it is 0. It is a positive penalty parameter used to strengthen the constraints of undirected acyclic graphs (DAGs).

[0091] This invention applies the actor-critic algorithm from the RL paradigm, with the expected reward function as the training objective. During training, it finds the graph with the best reward among all generated graphs and sets it as the output. However, due to the influence of confounding factors in practice, some edges that shouldn't exist in the graph may exist. Therefore, this invention requires further optimization using a greedy algorithm based on regression performance or the score function. For causal edges, this invention optimizes them using a causal inference method, which removes the parent node of a node and then calculates the score of the graph that retains the causal relationship between the remaining nodes. If the graph's score does not decrease or the decrease is within an acceptable range after implementing the optimization method, the optimization result is accepted, and processing continues based on the optimized graph. The actor-critic algorithm used in this invention provides immediate feedback from the critic, helping the actor learn the policy more stably and avoiding blind exploration in the policy space. The actor-critic algorithm typically requires fewer samples than pure policy gradient methods or value iteration methods, thus reducing training time and resource consumption. Simultaneously learning the policy and value function helps the model generalize better to unseen states, improving the model's application performance in different environments. When facing non-stationary environments (i.e., dynamically changing reward functions or environments), the actor-critic algorithm can adjust its policy more flexibly to adapt to environmental changes. Actors and critics can update in parallel, improving computational efficiency. By simultaneously considering policy and value, the actor-critic algorithm can reduce the risk of getting trapped in local optima and improve the global performance of the final policy.

[0092] Step 404: Extract the multi-step attack alarm sequence based on the multi-step attack relationship diagram: This application employs a time-based Depth-First Search (DFS) algorithm, considering node importance weights, to extract the main attack alarm sequences from the attack scenario graph. This effectively extends the traditional DFS method by adding time information, avoiding errors caused by disordered time sequences. Unlike the traditional Internet, each device node in the Industrial Internet performs a different role, thus different nodes have varying importance. Based on the time-based DFS algorithm, this application also considers node importance weights; these factors contribute to extracting the main attack alarm sequences from the multi-step attack relationship graph.

[0093] Step 405: Generate the target network based on the multi-step attack alert sequence: This process involves mapping alarm events to system devices, constructing an attack target network that includes attacker nodes and system device nodes, and combining this network with a multi-step attack alarm sequence and the system network topology. The diagram includes two types of nodes: attacker node A and system device node D. This step maps alarm events to the system devices corresponding to their IP addresses.

[0094] Step 406: Based on the target network, predict the attack intent: Depending on the target network, this step can employ various methods to predict attack intent, including: Method 1: Using link prediction, the link prediction function is defined as follows:

[0095] Where, vector Indicates all potential attack target devices d The score is denoted by n, where n is the number of devices. It is equipment d Embedded, This is a trainable transformation matrix. In real-world enterprise or industrial control networks, the function and importance level of devices influence the attacker's selection preferences. This step uses... Display device d The strength of the selected preference, that is, the sum of its importance based on its function, importance, and other aspects. , It was obtained from an expert in the field of industrial control system security. h a This indicates the ultimate intent to attack. From L Layered attack targets the network to obtain the embedding of the attacker's node at each layer. .

[0096] The different layers of embedding highlight the attacker's different preferences. Therefore, the final attack intent can be written as:

[0097] Method 2: Prediction using a graph neural network (GNN) model: Use a graph neural network (GNN) to extract attacker features from the target network, extract the spatiotemporal features of the target network through ST-GCN, and the spatiotemporal convolutional network can capture the temporal and spatial dependencies in the target network, which helps to more accurately model the features of APT attacks and predict the next attack target. Apply the relational attention mechanism to consider the dependencies in the attack sequence.

[0098] In summary, the source tracing and analysis method and system for APT attack detection proposed in this disclosure include at least the following technical points: 1. By using reinforcement learning to determine the causal relationships between alarm data, the impact of confounding factors (such as false alarms and useless alarms) on attack behavior analysis can be reduced.

[0099] 2. Combining the time dimension and node importance weights, a depth-first search (DFS) algorithm is used to identify malicious APT attack behaviors in the attack scenario graph.

[0100] 3. Construct the target network by combining the APT attack behavior sequence and device network topology information.

[0101] 4. Use GNNs to identify attack intent from the target graph and transform the attack prediction problem into a link prediction problem or a graph neural network (GNN) model problem.

[0102] This application can predict and identify APT attacks, thereby enabling proactive defensive measures. By accurately predicting attack targets, enterprises can better protect sensitive data and intellectual property. Enterprises can conduct preventative maintenance to avoid system downtime and data loss caused by attacks, reducing related maintenance and recovery costs. Timely attack prediction can reduce the need for emergency response, lower the workload and costs of emergency response teams, and optimize the allocation of network security resources based on predicted attack patterns and targets, thereby improving the overall efficiency of network security protection.

[0103] Figure 5 This is a schematic diagram of the structure of an APT attack detection tracing and analysis device proposed in one embodiment of this disclosure.

[0104] like Figure 5 As shown, the APT attack detection and tracing analysis device 50 includes: The acquisition module 501 is used to acquire alarm logs from the intrusion detection system and generate an adjacency matrix of attack scenarios based on the alarm logs. The first generation module 502 is used to identify the causal relationship between different attack behaviors based on the adjacency matrix of the attack scenario, so as to generate a multi-step attack relationship graph. Processing module 503 is used to extract multi-step attack alarm sequences based on the multi-step attack relationship diagram; The second generation module 504 is used to generate the attack target network based on the multi-step attack alarm sequence; The prediction module 505 is used to predict attack intent based on the target network.

[0105] It should be noted that the aforementioned explanation of the source tracing analysis method for APT attack detection also applies to the source tracing analysis device for APT attack detection in this embodiment, and will not be repeated here.

[0106] In this embodiment, alarm logs from the intrusion detection system are acquired, and an attack scenario adjacency matrix is ​​generated based on these logs. The causal relationships between different attack behaviors are identified using this adjacency matrix to generate a multi-step attack relationship graph. Multi-step attack alarm sequences are extracted from the multi-step attack relationship graph. An attack target network is generated based on these multi-step attack alarm sequences. Finally, attack intent is predicted based on the attack target network. Thus, by associating isolated alarms to generate an attack scenario graph and extracting key attack sequences using causal inference, a dynamically evolving attack target network is constructed. This allows for accurate characterization of attacker intent and multi-step attack paths, significantly improving the detection depth and prediction accuracy of complex APT attacks, and achieving a shift from passive alarms to proactive threat identification.

[0107] According to embodiments of this application, this application also provides an electronic device and a readable storage medium.

[0108] Figure 6 This is a block diagram of an electronic device according to an embodiment of this application.

[0109] like Figure 6 As shown, the electronic device includes: The memory 601, the processor 602, and the computer instructions stored in the memory 601 and executable on the processor 602.

[0110] When processor 602 executes instructions, it implements the source analysis method for APT attack detection provided in the above embodiments.

[0111] Furthermore, electronic devices also include: Communication interface 603 is used for communication between memory 601 and processor 602.

[0112] The memory 601 is used to store computer instructions that can be run on the processor 602.

[0113] The memory 601 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0114] The processor 602 is used to implement the source tracing analysis method for APT attack detection in the above embodiments when executing the program.

[0115] If the memory 601, processor 602, and communication interface 603 are implemented independently, then the communication interface 603, memory 601, and processor 602 can be interconnected via a bus to complete communication between them. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 6 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0116] Optionally, in a specific implementation, if the memory 601, processor 602, and communication interface 603 are integrated on a single chip, then the memory 601, processor 602, and communication interface 603 can communicate with each other through an internal interface.

[0117] The processor 602 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application.

[0118] This application also proposes a computer program product that, when executed by an instruction processor, implements the source analysis method for APT attack detection according to the embodiments of this application.

[0119] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0120] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0121] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0122] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0123] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0124] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0125] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0126] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A source tracing analysis method for APT attack detection, characterized in that, include: Obtain alarm logs from the intrusion detection system and generate an adjacency matrix of attack scenarios based on the alarm logs; Based on the adjacency matrix of the attack scenario, the causal relationship between different attack behaviors is identified to generate a multi-step attack relationship graph; Based on the multi-step attack relationship diagram, multi-step attack alarm sequence extraction is performed; Based on the multi-step attack alert sequence, generate the target network for the attack. Based on the target network, attack intent is predicted.

2. The method as described in claim 1, characterized in that, The step of generating an adjacency matrix for attack scenarios based on the alarm logs includes: The alarm logs are converted into preset tuple format data, and the tuple format data is converted into alarm vectors through word embedding. The tuple format data includes source IP, destination IP, source port, destination port, protocol, timestamp, attack type, and related data of behavioral characteristics. The alarm vector is processed using an attention-based encoder-decoder model to generate the adjacency matrix of the attack scenario representing the relationship between attack behaviors. The attention-based encoder-decoder model performs dimensionality reduction and feature extraction on the behavioral features through an autoencoder.

3. The method as described in claim 1, characterized in that, The step of identifying the causal relationships between different attack behaviors based on the adjacency matrix of the attack scenario to generate a multi-step attack relationship graph includes: Based on the adjacency matrix of the attack scenario, a set of acyclic graphs is generated by traversing the graph. The acyclic graph set is used as training data by root traversal, and reinforcement learning is performed using the actor-critic algorithm. The acyclic graph with the best reward score is then output as the multi-step attack relationship graph.

4. The method as described in claim 1, characterized in that, The step of extracting multi-step attack alarm sequences based on the multi-step attack relationship graph includes: Determine the node attributes in the multi-step attack relationship graph, wherein the node attributes include timestamps and node importance weights; Based on the timestamp and the node importance weight, a depth-first search algorithm is executed to extract the multi-step attack alarm sequence from the multi-step attack relationship graph. The search path selection strategy of the depth-first search algorithm is constrained by both time order and node importance weight.

5. The method as described in claim 1, characterized in that, The step of generating the target network based on the multi-step attack alert sequence includes: Obtain the topology information of the system network; Each alarm event in the multi-step attack alarm sequence is mapped to a corresponding system device to create a system device node; Based on the source IP information of the alarm event, an attacker node is created; Based on the topology information, edges are connected between the attacker node and the system device node, as well as edges between different system device nodes, to obtain the attack target network.

6. The method as described in claim 1, characterized in that, The step of predicting attack intent based on the target network includes any one of the following: The target network is processed using a link prediction method based on a preset link prediction function in order to predict the attack intent. or, Attacker features are extracted from the target network based on graph neural networks, spatiotemporal features of the target network are extracted based on spatiotemporal convolutional networks, and attack intent is predicted by combining the attacker features and the spatiotemporal features.

7. A source tracing and analysis device for APT attack detection, characterized in that, include: The acquisition module is used to acquire alarm logs from the intrusion detection system and generate an attack scenario adjacency matrix based on the alarm logs. The first generation module is used to identify the causal relationship between different attack behaviors based on the adjacency matrix of the attack scenario, so as to generate a multi-step attack relationship graph. The processing module is used to extract multi-step attack alarm sequences based on the multi-step attack relationship graph. The second generation module is used to generate the attack target network based on the multi-step attack alarm sequence; The prediction module is used to predict the attack intent based on the target network.

8. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-6.

9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, in, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Security event detection method and device, equipment and storage medium

    CN116996315A

  • Abnormal point rapid detection and attack scene reconstruction method and system based on traceability graph

    CN117411699A

  • Security alarm driven attack scene reconstruction method, system and device and medium

    CN117596071A

  • APT attack detection and tracing method based on log

    CN119299214A

  • APT attack detection method and system, storage medium and electronic equipment

    CN119603008A