A target field federation cross-domain threat judgment method and system

By generating standardized intermediate representations for assessment through localized preprocessing and threat semantic ontology models, and combining encrypted communication and Bayesian network fusion inference, the problems of coarse information granularity and insufficient security in cross-domain threat assessment are solved, and high-precision cross-domain threat collaborative analysis and attack chain identification are achieved.

CN121603305BActive Publication Date: 2026-03-27SICHUAN YILAN SITUATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-28
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing technologies for cross-domain threat assessment suffer from problems such as coarse-grained summary information, single-dimensional event correlation, insufficient security of communication mechanisms, and lack of time-series alignment capabilities in convergence analysis. These issues make it difficult to achieve high-precision, low-latency, and traceable regional-level collaborative threat assessment while ensuring data sovereignty and privacy compliance.

Method used

The raw security data is converted into a structured event stream through localized preprocessing, and a standardized intermediate representation for judgment is generated based on the threat semantic ontology model. The data is transmitted through an encrypted communication channel, and a cross-domain temporal event graph is constructed by combining cross-domain entity disambiguation processing and Bayesian network multi-source evidence fusion reasoning to identify high-confidence attack sequences.

Benefits of technology

It achieves a balance between data privacy protection and collaborative analysis in cross-domain threat assessment, improves the accuracy and reliability of cross-domain attack chain reconstruction and advanced persistent threat behavior identification, and ensures information security and access control compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121603305B_ABST
    Figure CN121603305B_ABST
Patent Text Reader

Abstract

The application discloses a target range federation cross-domain threat judgment method and system, aiming at solving the problems of cross-domain threat correlation analysis difficulty, entity fragmentation and low judgment precision caused by the fact that original security data of multiple target ranges cannot be shared. The method comprises the following steps: each sub-target range locally performs structural processing and high-order semantic coding on the original security data to generate a standardized judgment intermediate representation; a central coordination node performs cross-domain entity disambiguation and constructs a time sequence event graph based on the intermediate representation, and outputs a global threat judgment conclusion by fusing multi-source evidence through a Bayesian network; and the result is returned to the relevant target range according to a permission policy to form a closed-loop feedback. The system comprises a judgment agent unit deployed in each sub-target range and a central coordination node, which respectively realize local feature extraction and collaborative reasoning. The application realizes cross-domain accurate restoration and collaborative defense of complex threats such as APT attack chains on the premise of guaranteeing that the original data does not go out of the domain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, specifically, it relates to a method and system for assessing cross-domain threats in a target range federation. Background Technology

[0002] With the large-scale deployment of cyber ranges in national-level critical information infrastructure, industry security drills, and regional offensive and defensive confrontations, multi-location and multi-unit independently constructed sub-range systems are gradually forming a distributed federated architecture. As a highly realistic and highly isolated cybersecurity testing environment, the core function of a cyber range is to reproduce real cyberattack behaviors, verify the effectiveness of defense strategies, and support threat assessment decisions. In this context, cross-domain collaboration has become a key requirement for improving overall security situation awareness capabilities. However, range data, due to its involvement of sensitive topologies, vulnerability details, and attack samples, is usually subject to strict local management and privacy compliance constraints, making direct cross-domain exchange impossible.

[0003] Among these, the range-fed cross-domain threat assessment focuses on achieving correlation analysis of security events across multiple ranges and constructing a global threat view under the principle of "data not leaving the domain." The core objective of this direction is to support cross-domain attack path reconstruction and advanced persistent threat (APT) behavior identification by sharing only lightweight, anonymized intermediate assessment results, rather than raw logs or full traffic data. However, existing technologies face significant bottlenecks in this scenario: on the one hand, traditional centralized Security Information and Event Management (SIEM) platforms require the unified aggregation of raw data from various ranges to a central node for analysis. While this has strong correlation capabilities, it violates data localization regulatory requirements, and the massive data transmission leads to high latency and bandwidth pressure. On the other hand, some systems use simple alarm reporting mechanisms, only transmitting isolated attack event labels, lacking structured context and temporal logic, making it difficult to support dynamic connection and causal reasoning of cross-range attack chains.

[0004] Existing technologies for cross-domain threat assessment generally suffer from problems such as coarse-grained summary information, single-dimensional event correlation, insufficient security of communication mechanisms, and lack of time-series alignment capabilities in convergence analysis. Specifically, most solutions fail to standardize and structure local assessment results, leading to semantic inconsistencies between heterogeneous target ranges; the cross-domain exchange process lacks efficient integrity verification and low-overhead encrypted channels, making it vulnerable to man-in-the-middle attacks or data tampering; and the central node, after receiving multi-source summaries, lacks an automated attack path splicing algorithm based on IP jump relationships and time sliding windows, failing to effectively identify cross-domain lateral movement behavior. These shortcomings make it difficult for existing methods to achieve high-precision, low-latency, and traceable regional-level collaborative threat assessment while ensuring data sovereignty and privacy compliance. Therefore, there is an urgent need for an engineered and implementable target range federated cross-domain threat assessment system and method. Summary of the Invention

[0005] The purpose of this invention is to provide a target range federation cross-domain threat assessment method and system, which mainly solves the problems that existing technologies generally have in cross-domain threat assessment, such as coarse granularity of summary information, single event correlation dimension, insufficient security of communication mechanism, and lack of time sequence alignment capability in convergence analysis.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0007] A method for assessing cross-domain threats in a target range federal network includes the following steps:

[0008] S1, the raw security data generated within each of the multiple sub-ranges is obtained through the deployment modules of the federated nodes; and the raw security data is preprocessed locally to form a structured local event stream;

[0009] S2, based on the preset threat semantic ontology model, high-order feature extraction and semantic encoding are performed on the structured local event stream to generate a standardized intermediate representation for judgment;

[0010] S3, the standardized intermediate representation is uploaded to the central coordination node through an encrypted communication channel, and cross-domain entity disambiguation processing is performed to normalize and merge the identifiers pointing to the same physical entity or logical object in different target ranges.

[0011] S4. Based on the normalized entity identifiers, a cross-domain temporal event graph is constructed. Multi-source evidence fusion reasoning is performed on the cross-domain temporal event graph to calculate the posterior probability distribution of global threat events and identify high-confidence attack sequences with cross-domain association.

[0012] S5. Based on the posterior probability distribution of the global threat events, generate a global threat assessment report. Then, send the subset of content related to a specific sub-range in the global threat assessment report back to the corresponding sub-range assessment agent unit according to a preset permission policy. This is used to update the local threat knowledge base and trigger defense response actions.

[0013] Further, in step S1, the raw security data includes network traffic packets, system operation logs, intrusion detection alarm records, and red team / blue team behavioral trajectories; the localization preprocessing of the raw security data includes:

[0014] Timestamps from different acquisition sources are uniformly converted to Coordinated Universal Time format and calibrated to microsecond-level accuracy;

[0015] Network traffic packets are decapsulated layer by layer to extract source address, destination address, source port, destination port, protocol type, and application layer characteristics;

[0016] An irreversible transformation based on the national cryptographic SM3 hash function is used to map the original IPv4 or IPv6 address into a fixed-length hexadecimal string as a logical identifier.

[0017] The continuous adversarial behavior trajectory or alarm sequence is broken down into independent atomic events according to the tactical stage, and each atomic event corresponds to a single attack technique.

[0018] Furthermore, the specific process of step S2 is as follows:

[0019] S21, the threat semantic ontology model defines a standardized description framework for attack behavior, the core elements of which include attacker role type, attack target category, initial access method, execution payload type, persistence mechanism, privilege escalation path, defense and evasion methods, credential access strategy, detection and reconnaissance range, lateral movement technology, command and control channel characteristics and data leakage mode.

[0020] S22, traverse each record in the local event stream, match the corresponding element values ​​in the ontology model based on its behavioral characteristics, and generate structured codes;

[0021] S23, the output of the standardized judgment intermediate is represented as a five-tuple, which includes the attacker's identifier, target asset fingerprint, tactical and technical process number, confidence score and time window.

[0022] Furthermore, in step S3, the specific process of performing cross-domain entity disambiguation is as follows:

[0023] Based on the asset fingerprint mapping table that is uniformly maintained and periodically distributed by the central coordination node, the fingerprints of the target assets are normalized.

[0024] Calculate the Jaccard similarity coefficient of attack subjects on the tactical and technical process usage sets in different target ranges;

[0025] When the Jaccard similarity coefficient exceeds a preset threshold, it is determined to be the activity of the same attacking entity in different target ranges, and a unified cross-domain entity identifier is assigned.

[0026] Furthermore, in step S4, the specific process of constructing the cross-domain temporal event graph is as follows:

[0027] Create a node for each new attacking entity, target asset, and intermediate stepping stone;

[0028] For each attack event, a directed edge is created, with edge attributes including source node identifier, target node identifier, tactical process number, occurrence timestamp, and confidence weight.

[0029] Iterate through all standardized intermediate representations in chronological order, update the existing edge attributes in the graph, and perform graph connectivity analysis to identify potential attack path segments.

[0030] Furthermore, the specific process of performing multi-source evidence fusion reasoning on the cross-domain temporal event graph is as follows:

[0031] Load a predefined Bayesian network model, whose node variables include whether a single point attack event actually occurs, whether the attack chain phase is completed, and whether the global attack intent is valid.

[0032] The confidence scores uploaded by each sub-range are used as the prior probability input for single-point attack event nodes;

[0033] By using the belief propagation algorithm, combined with attack chain integrity constraints and tactical evolution logic, the posterior probability distribution of global threat events is calculated.

[0034] Furthermore, in step S5, the specific process for generating the global threat assessment report is as follows:

[0035] The complete attack chain from the initial entry point to the final target is displayed graphically, and the tactical and technical processes used in each stage are marked.

[0036] List the key springboard nodes that act as relays during lateral movement; summarize the logical identifiers of all attacked or scouted assets and associate them with their respective units;

[0037] The risk level assessment value is calculated based on the posterior probability distribution, asset security level, and attack impact range, and is divided into four levels: low, medium, high, and emergency.

[0038] Further, in step S5, the permission policy is:

[0039] Only information related to the assets of this organization or attacks initiated by this organization should be returned;

[0040] Before the data is sent back, a second desensitization process is performed to remove entity identifiers that are directly associated with other units and replace asset nodes of other units with generic placeholders.

[0041] A range-based federal cross-domain threat assessment system for implementing the above method includes:

[0042] The Federation node deployment module is used to acquire raw security data generated within their respective test ranges;

[0043] The summary generation module, based on a preset threat semantic ontology model, performs high-order feature extraction and semantic encoding on the structured local event stream;

[0044] The cross-domain exchange module is used to upload the standardized intermediate representation to the central coordination node through an encrypted communication channel, perform cross-domain entity disambiguation processing, and construct a cross-domain time-series event graph.

[0045] The aggregation and analysis module performs multi-source evidence fusion reasoning on the cross-domain time-series event graph, generates a global threat analysis report, and sends it back to the corresponding sub-range analysis agent unit according to the preset permission policy.

[0046] Compared with the prior art, the present invention has the following beneficial effects:

[0047] (1) This invention converts the original security data into a structured event stream through localized preprocessing, and generates a lightweight standardized intermediate representation for judgment based on the threat semantic ontology model. Only the intermediate representation is uploaded instead of the original data. At the same time, the national cryptographic SM3 hash function is used to realize the irreversible desensitization mapping of IP addresses, which not only protects the original data sovereignty and privacy compliance of each sub-target, but also significantly reduces the bandwidth consumption and latency of cross-domain transmission, thus achieving a balance between data privacy protection and cross-domain collaborative analysis.

[0048] (2) This invention unifies the semantic description framework of heterogeneous target range events through a threat semantic ontology model, ensuring semantic consistency of events in different target ranges; it combines cross-domain entity disambiguation processing to achieve normalized identification of the same physical / logical entity, and constructs a cross-domain time-series event graph to connect the time series and causal relationships of multiple target range events; and then calculates the posterior probability distribution of global threat events through Bayesian network multi-source evidence fusion reasoning, effectively identifying high-confidence attack sequences with cross-domain association, thus solving the core problem of cross-target attack chain reconstruction and advanced persistent threat (APT) behavior identification.

[0049] (3) The present invention uses an encrypted communication channel to ensure the confidentiality and integrity of the transmission of the standardized assessment intermediate representation, and prevents man-in-the-middle attacks and data tampering; by using a preset permission policy, only a subset of assessment reports related to the sub-target range are sent back, and a secondary desensitization process is performed to remove the associated identifiers of other units, ensuring information security and permission compliance; at the same time, the construction of the cross-domain time-series event map realizes the time-series alignment and connectivity analysis of events in multiple target ranges, effectively identifies cross-domain lateral movement behavior, and improves the accuracy and reliability of global threat assessment. Attached Figure Description

[0050] Figure 1 This is a flowchart illustrating the evaluation method of the present invention. Detailed Implementation

[0051] The present invention will be further described below with reference to the accompanying drawings and embodiments. The embodiments of the present invention include, but are not limited to, the following embodiments.

[0052] like Figure 1As shown, this invention discloses a target range federation cross-domain threat assessment method and system. Its core lies in constructing a three-layer federation architecture, which consists of a federation node deployment module, a central coordination node, and a secure communication channel between the two. The entire system, while ensuring that the original security data does not leave the domain, achieves in-depth correlation analysis of threat events across multiple target ranges and dynamic fusion of the global security situation.

[0053] First, raw security data generated within each of the multiple sub-ranges is acquired through the deployment modules of federated nodes. This raw security data includes network traffic packets, system operation logs, intrusion detection alarm records, and red team / blue team exercise behavior sequences. Network traffic packets are captured in real-time via mirrored ports or probe devices, containing transport layer and application layer protocol fields; system operation logs are collected by the operating system audit module or security information and event management platform, recording critical operations such as user login, process startup, and file access; intrusion detection alarm records originate from intrusion detection systems deployed at the range boundary or on internal hosts, identifying identified suspicious behavior patterns; and red team / blue team exercise behavior sequences are recorded by the range exercise management system, including the attacker's toolchain, penetration path, exploited vulnerabilities, and the defender's response sequence. All raw security data is stored in a local security database and accessed by subsequent processing modules through a unified data access interface.

[0054] Subsequently, the raw security data undergoes localized preprocessing. This preprocessing includes four mandatory sub-steps: timestamp normalization, protocol field parsing, IP address de-identification mapping, and attack behavior atomic segmentation. Timestamp normalization converts timestamps from different collection sources into Coordinated Universal Time (UTC) format and calibrates them to microsecond precision to eliminate event sequencing errors caused by system clock deviations. Protocol field parsing decapsulates network traffic packets layer by layer to extract source address, destination address, source port, destination port, protocol type, payload length, and application layer characteristics such as HTTP request methods, URL paths, and User-Agent strings. IP address de-identification mapping uses an irreversible transformation based on the SM3 hash function to map the original IPv4 or IPv6 address to a fixed-length hexadecimal string. This string serves as a logical identifier for subsequent processing and cannot be used to reconstruct the original address through any computational means. Attack behavior atomization breaks down continuous adversarial behavior trajectories or alarm sequences into independent atomic events according to tactical phases. Each atomic event corresponds to a single attack technique, such as "exploiting the EternalBlue vulnerability," "performing a Mimikatz credential dump," or "establishing a Cobalt Strike beacon connection." After the above processing, a structured local event stream is formed, in which each event record includes anonymized subject identifier, target identifier, timestamp, protocol feature vector, behavior type label, and original data source identifier.

[0055] Next, based on a pre-defined threat semantic ontology model, high-order feature extraction and semantic encoding are performed on the structured local event stream. The threat semantic ontology model defines a standardized descriptive framework for attack behavior, with core elements including attacker role type, target category, initial access method, execution payload type, persistence mechanism, privilege escalation path, defense evasion methods, credential access strategy, detection and reconnaissance scope, lateral movement techniques, command and control channel characteristics, and data infiltration patterns. Each element corresponds to a predefined set of enumerated values. For example, attacker role types include external hackers, internal personnel, and automated scripts; initial access methods include spear phishing, remote service exploitation, and supply chain poisoning; and lateral movement techniques include pass-the-hash, WMI remote execution, and PsExec calls. The semantic encoding module traverses each record in the local event stream, matches its behavioral characteristics to the corresponding element values ​​in the ontology model, and generates structured encoding. The final standardized assessment intermediate is represented as a quintuple, containing the attacker's identifier, target asset fingerprint, tactical process number, confidence score, and time window. Both the attacker's identifier and the target asset fingerprint are generated using the aforementioned SM3 hash mapping; the tactical and technical process number follows the numbering system of the MITRE ATT&CK framework, such as T1059 indicating command script execution; the confidence score is calculated by the local analysis engine based on the reliability of the alarm source, the degree of behavior matching, and the consistency of the context, and the value range is an integer from 0 to 100; the time window defines the validity period of this intermediate representation, which is usually 72 hours after the event occurs.

[0056] After semantic encoding is completed, the standardized intermediate representation for analysis is uploaded to the central coordination node via an encrypted communication channel. The establishment of the encrypted communication channel includes two-way digital certificate authentication and session key negotiation. Each sub-range's analysis agent unit and the central coordination node are pre-installed with digital certificates issued by a trusted certificate authority, containing a public key and identity identifier. Upon initiation of communication, both parties exchange certificates and verify each other's legitimacy, subsequently generating a session key based on the Elliptic Curve Diffie-Hellman key exchange protocol. During data transmission, all standardized intermediate representations for analysis are encrypted using the national cryptographic algorithm SM4 in CBC mode, with a message authentication code generated based on the SM3 algorithm appended to the ciphertext to ensure integrity. After receiving the uploaded data, the central coordination node's secure access gateway performs identity authentication, integrity verification, and decryption. Only when all three verifications pass is the plaintext data handed over to subsequent modules for processing.

[0057] At the central coordination node, standardized intermediate representations for analysis are received from all sub-ranges, and cross-domain entity disambiguation is performed. This process relies on two core resources: a shared asset fingerprint mapping table across multiple ranges and an attack subject behavior similarity clustering algorithm. The asset fingerprint mapping table is maintained uniformly by the central coordination node, recording the mapping relationship between the de-identified logical identifier of an asset and its affiliated unit, asset type, security level, and functional role. When each sub-range generates asset fingerprints locally, it performs consistent encoding according to the rules in this mapping table, ensuring that the same physical asset generates the same logical identifier in different ranges. The cross-domain entity disambiguation module first normalizes the target asset fingerprint according to the asset fingerprint mapping table, merging different representations pointing to the same asset into a unique identifier. For the attack subject identifier, since it is generated based on the local IP address, the same attacker may have different identifiers in different ranges. Therefore, an attack subject behavior similarity clustering algorithm is used for processing. This algorithm calculates the Jaccard similarity coefficient of the attack subjects in different ranges on the set of tactical and technical processes used, expressed by the formula:

[0058]

[0059] in, and These represent the sets of tactical techniques used by attackers A and B, respectively. When the calculated Jaccard similarity coefficient exceeds a preset threshold of 0.75, they are determined to be the activities of the same attacker in different target ranges, and a unified cross-domain entity identifier is assigned. This clustering process uses a hierarchical clustering algorithm, merging entity clusters with similarity higher than the threshold from bottom to top until convergence.

[0060] Based on normalized entity identifiers, a cross-domain temporal event graph is constructed. This graph is organized as a directed graph, with node types including attack entity nodes, target asset nodes, and intermediate stepping stone nodes, and edges representing attack actions. Each edge contains a set of attributes: source node identifier, target node identifier, tactical / technical process number, occurrence timestamp, and confidence weight. The graph construction module traverses all standardized intermediate representations in chronological order, creating a node for each newly appearing entity and a directed edge for each attack event. If edges with the same source-target pair already exist in the graph, the edge attributes are updated according to the timestamp, retaining the latest event information. Simultaneously, the module performs graph connectivity analysis to identify potential attack path segments, such as sequences from the initial access node through privilege escalation nodes to lateral movement nodes.

[0061] Subsequently, multi-source evidence fusion inference is performed on the cross-domain time-series event graph. This inference process employs a Bayesian network model, the structure of which is determined by predefined attack chain logic rules. The node variables of the Bayesian network include three categories: whether a single attack event actually occurred, whether the attack chain phase was completed, and whether the global attack intent was valid. The conditional probability table is obtained through offline training using historical analysis data, reflecting the statistical dependencies between variables. During inference, the confidence scores uploaded from each sub-target range are used as the prior probability input for single attack event nodes. Combined with attack chain integrity constraints (e.g., lateral movement phases must occur after initial access and privilege escalation) and tactical evolution logic (e.g., credentialed access usually occurs before privilege escalation), the posterior probability distribution of the global threat event is calculated using a belief propagation algorithm. This process can identify high-confidence attack sequences with cross-domain associations; even if the local evidence from a single target range is weak, multi-source collaboration can significantly improve the overall confidence. The mathematical expression of Bayesian network inference is as follows:

[0062]

[0063] in, This indicates the global attack hypothesis. This represents the observed set of multi-source evidence. For prior probability, Likelihood function, Let be the posterior probability.

[0064] Based on the posterior probability distribution of global threat events, a global threat assessment report is generated. This report comprises four core components: a cross-domain attack path topology map, a list of key relay nodes, the scope of affected assets, and risk level assessment values. The cross-domain attack path topology map graphically displays the complete attack chain from the initial entry point to the final target, annotating the tactical techniques used at each stage; the list of key relay nodes lists assets that act as relays during lateral movement, and these nodes are typically the focus of subsequent defense hardening; the scope of affected assets summarizes the logical identifiers of all attacked or scouted assets and associates them with their respective units; the risk level assessment values ​​are calculated based on the posterior probability distribution, asset security level, and the scope of attack impact, and are categorized into four levels: low, medium, high, and critical.

[0065] Finally, the subset of content related to specific sub-ranges from the global threat assessment report is sent back to the corresponding sub-range assessment agent unit according to a preset permission policy. The permission policy stipulates that only information related to the unit's assets or attacks initiated by the unit is allowed to be sent back. The policy-based backhaul module performs secondary de-identification processing before distribution, removing entity identifiers directly associated with other units, such as replacing asset nodes of other units in cross-domain attack paths with generic placeholders. The backhauled content is transmitted in reverse through the aforementioned encrypted communication channel. After receiving it, the assessment agent unit in the sub-range federated node deployment module stores it in the local threat knowledge base and triggers defense response actions, such as updating firewall rules, isolating infected hosts, or adjusting intrusion detection policies.

[0066] At the system level, the assessment system includes a federated node deployment module for acquiring raw security data generated within their respective target ranges; a summary generation module for extracting high-order features and semantically encoding structured local event streams based on a pre-defined threat semantic ontology model; a cross-domain exchange module for uploading standardized intermediate representations of the assessment to the central coordination node via an encrypted communication channel, performing cross-domain entity disambiguation processing, and constructing a cross-domain time-series event graph; and a convergence and assessment module for performing multi-source evidence fusion reasoning on the cross-domain time-series event graph, generating a global threat assessment report, and sending it back to the corresponding sub-target range assessment agent unit according to a pre-defined permission policy. All modules communicate with each other via an internal message bus to ensure the orderly transmission and processing of data streams.

[0067] Throughout the system's operation, each sub-range maintains data sovereignty, with raw security data always stored locally, and only semantically rich intermediate representations uploaded. The central coordination node does not store raw data, only processing temporary intermediate representations and generated global reports. This design strictly adheres to the principles of data minimization and cybersecurity compliance requirements, while supporting cross-domain reconstruction of complex APT attack chains, lateral movement paths, and multi-stage penetration behaviors, achieving a leap in overall security capabilities for regional and industry-level federated range systems.

[0068] The above embodiments are merely one of the preferred embodiments of the present invention and should not be used to limit the scope of protection of the present invention. Any modifications or refinements made to the main design concept and spirit of the present invention that are not of substantial significance, but solve the same technical problem as the present invention, should be included within the scope of protection of the present invention.

Claims

1. A method for federated cross-domain threat assessment of a target range, characterized in that, The method comprises the following steps: S1, obtaining original security data generated in each target field by a federal node deployment module of a plurality of sub-target fields respectively; and performing local preprocessing on the original security data to form a structured local event stream; wherein the local preprocessing process comprises four mandatory sub-steps: timestamp normalization, protocol field analysis, IP address desensitization mapping, and attack behavior atomization division; S2, based on a preset threat semantic ontology model, performing high-order feature extraction and semantic coding on the structured local event stream to generate a standardized research and judgment intermediate representation; the specific process is as follows: S21, the threat semantic ontology model defines a standardized description framework of attack behaviors, and the core elements include attacker role type, attack target category, initial access method, execution payload type, persistence mechanism, privilege escalation path, defense evasion means, credential access strategy, discovery reconnaissance range, lateral movement technology, command control channel characteristics, and data exfiltration mode; S22, traversing each record in the local event stream, matching the corresponding element value in the ontology model according to the behavior characteristics, and generating a structured code; S23, the output standardized research and judgment intermediate representation is a five-tuple, including attack subject identification, target asset fingerprint, tactical and technical process number, confidence score, and time window; S3, uploading the standardized research and judgment intermediate representation to the central coordination node through an encrypted communication channel, and performing cross-domain entity disambiguation processing to normalize and combine the identifications of the same physical entity or logical object in different target fields; wherein the specific process of performing cross-domain entity disambiguation processing is as follows: According to the asset fingerprint mapping table uniformly maintained and periodically distributed by the central coordination node, the target asset fingerprint is normalized; wherein the asset fingerprint mapping table is uniformly maintained by the central coordination node, and records the mapping relationship between the desensitized asset logical identification and its belonging unit, asset type, security level and function role; Calculate the Jaccard similarity coefficient of the attack subject in the tactical and technical process use set in different target fields; When the Jaccard similarity coefficient exceeds a preset threshold, it is determined that the same attack subject is active in different target fields, and a unified cross-domain subject identification is assigned; S4, based on the normalized entity identification, constructing a cross-domain time sequence event graph, performing multi-source evidence fusion reasoning on the cross-domain time sequence event graph, calculating the posterior probability distribution of the global threat event, and identifying the cross-domain related high-confidence attack sequence; wherein the specific process of constructing the cross-domain time sequence event graph is as follows: Create a node for each newly appearing attack subject, target asset and intermediate jump station; Create a directed edge for each attack event, and the edge attribute includes source node identification, target node identification, tactical and technical process number, occurrence timestamp and confidence weight; Traverse all standardized research and judgment intermediate representations in chronological order, update the edge attribute of the existing edge in the graph, and perform graph connectivity analysis to identify potential attack path fragments; The specific process of performing multi-source evidence fusion reasoning on the cross-domain time sequence event graph is as follows: loading a Bayesian network model with a predefined structure, node variables of which include whether a single-point attack event actually occurs, whether an attack chain stage is completed, and whether a global attack intention is true; inputting confidence scores uploaded by each sub-target field as prior probabilities of the single-point attack event node; calculating a posterior probability distribution of the global threat event through a belief propagation algorithm, combined with attack chain integrity constraint rules and tactical evolution logic; S5, generating a global threat research and judgment report according to the posterior probability distribution of the global threat event, and returning a subset of the global threat research and judgment report related to a specific sub-target field to a corresponding sub-target field research and judgment agent unit according to a preset permission policy, for updating a local threat knowledge base and triggering a defense response action. 2.The target field federal cross-domain threat judgment method according to claim 1, characterized in that, In the step S1, the original security data includes network traffic messages, system operation logs, intrusion detection alarm records, and red-blue confrontation behavior trajectories; The local preprocessing of the original security data includes: Converting timestamps from different collection sources into coordinated universal time format and calibrating them to microsecond level precision; Unpacking network traffic messages layer by layer to extract source address, destination address, source port, destination port, protocol type and application layer features; Mapping original IPv4 or IPv6 addresses into fixed-length hexadecimal strings as logical identifiers using an irreversible transformation based on the SM3 hash function of the national standard; Splitting continuous confrontation behavior trajectories or alarm sequences into independent atomic events according to tactical stages, each atomic event corresponding to a single attack technique. 3.The target range federal cross-domain threat judgment method according to claim 2, characterized in that, In the step S5, the specific process of generating a global threat research and judgment report is as follows: Displaying the complete attack chain from the initial entry point to the final target in a graphical manner, and marking the tactical techniques used in each stage; Listing key hop-on nodes that play a relay role in lateral movement; summarizing all attacked or scouted asset logical identifiers and associating them with their respective units; Based on the posterior probability distribution, asset security level and attack impact range, the risk level evaluation value is calculated, which is divided into four levels: low, medium, high and urgent.

4. The target range federal cross-domain threat judgment method according to claim 3, characterized in that, In the step S5, the permission policy is: Only return information related to the assets of the unit or attack behaviors initiated by the unit; Performing secondary desensitization processing before returning, removing entity identifiers directly associated with other units, and replacing asset nodes of other units with general placeholders.

5. A target range federal cross-domain threat judgment system, characterized in that, A method for implementing the target field federation cross-domain threat research and judgment method according to any one of claims 1-4, comprising: A federation node deployment module for obtaining original security data generated inside each target field; An abstract generation module for performing high-order feature extraction and semantic coding on the structured local event stream based on a preset threat semantic ontology model; A cross-domain exchange module for uploading the standardized research and judgment intermediate representation to the central coordination node through an encrypted communication channel, performing cross-domain entity disambiguation processing, and constructing a cross-domain time sequence event graph; A convergence and research module for performing multi-source evidence fusion reasoning on the cross-domain time sequence event graph, generating a global threat research and judgment report, and returning the report to the corresponding sub-target field research and judgment agent unit according to a preset permission policy.

Citation Information

Patent Citations

  • Network deep threat detection method

    CN111431865A

  • Multi-source threat intelligence privacy fusion processing method and system

    CN120896725A