Log association analysis method and system for network abnormal operation behavior

By performing normalized element analysis and temporal dependency mining on multi-source heterogeneous logs, potential threat patterns are generated. Proactive traversal matching and reverse inference are then performed, solving the problems of format differences and insufficient evaluation in the correlation analysis of network abnormal operation behavior logs, thus improving analysis efficiency and reliability.

CN121706050AInactive Publication Date: 2026-03-20GANSU ELECTRIC POWER TIANSHUI POWER SUPPLY
View PDF 0 Cites 2 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-11
Publication Date
2026-03-20
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In existing technologies for log correlation analysis of abnormal network operations, the format differences and semantic discrepancies of multi-source heterogeneous logs lead to incomplete parsing of log elements, insufficient mining of temporal dependencies, inability to accurately capture potential correlations and threat patterns, and lack of scientific evaluation mechanisms, thus affecting the efficiency and reliability of the analysis.

Method used

By normalizing and parsing elements from multi-source heterogeneous logs to form standardized events, performing time-series dependency mining and multi-dimensional quantitative assessment, generating potential threat patterns, conducting proactive traversal matching and reverse inference, generating verification probe strategies, carrying out incremental data collection and threat assessment, and generating an analysis report.

Benefits of technology

It enables accurate extraction and unified representation of standardized events, improves the completeness and accuracy of threat path identification, enhances the efficiency of log correlation analysis and the credibility of assessment reports, and provides reliable support for network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121706050A_ABST
    Figure CN121706050A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of log analysis, and discloses a log association analysis method and system for a network abnormal operation behavior, and the method comprises the steps: carrying out the normalized element analysis of a multi-source heterogeneous log of a target network environment, and obtaining a standardized event of the multi-source heterogeneous log; performing time sequence dependence mining on the standardized event to obtain a potential threat mode of the standardized event; performing active traversal matching on the standardized events to obtain a candidate associated event sequence of the standardized events; performing reverse deduction on a subsequent evolution stage of the target network environment to obtain a verification probe strategy of the subsequent evolution stage; applying the verification probe strategy to the target network environment, and performing data acquisition on the target network environment to obtain verification feedback data of the target network environment; performing threat degree evaluation on the candidate associated event sequence to obtain a research and judgment report of the target network environment; according to the invention, the efficiency of log association analysis of network abnormal operation behaviors can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of log analysis technology, and in particular to a method and system for log correlation analysis of abnormal network operation behavior. Background Technology

[0002] In the scenario of log correlation analysis of abnormal network operation behavior, the format differences and semantic discrepancies of multi-source heterogeneous logs constitute the core obstacle to data processing. Existing technologies have failed to achieve efficient normalization and parsing of log elements, resulting in defects in the completeness and accuracy of the extraction of standardized events. This leads to a lack of a unified and reliable data foundation for subsequent correlation analysis, directly restricting the overall efficiency of the analysis process.

[0003] Existing technologies have significant shortcomings in time-series dependency mining and threat pattern identification. They struggle to accurately capture the potential correlations and evolutionary logic between standardized events and lack a scientifically sound, multi-dimensional quantitative evaluation mechanism, making it difficult to effectively screen high-value threat paths. Furthermore, the design of verification strategies and threat level assessment methods for candidate related event sequences are inadequate, resulting in difficulties in ensuring the reliability and timeliness of the analysis results. This fails to meet the core requirements of network security protection for accurate identification and rapid response to abnormal behavior. Therefore, improving the efficiency of log correlation analysis of abnormal network operations has become an urgent problem to be solved. Summary of the Invention

[0004] This invention provides a method and system for log correlation analysis of abnormal network operation behavior to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, this invention provides a log correlation analysis method for abnormal network operation behavior, comprising: S01. Normalize the elements of the multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous logs. S02. Perform time-series dependency mining on the standardized events to obtain the potential threat patterns of the standardized events; S03. Based on the potential threat pattern, actively traverse and match the standardized events to obtain a candidate associated event sequence of the standardized events; S04. Based on the candidate associated event sequence, reverse the evolution of the target network environment to obtain the verification probe strategy for the subsequent evolution stage. S05. Apply the verification probe strategy to the target network environment and perform incremental data collection on the target network environment to obtain verification feedback data of the target network environment. S06. Based on the verification feedback data, assess the threat level of the candidate associated event sequence to obtain an analysis report of the target network environment.

[0006] In a preferred embodiment, the step of normalizing the elements of the multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous logs includes: A general format adaptation is performed on the multi-source heterogeneous logs of the target network environment to obtain formatted entries for the target network environment; The formatted entries are summarized using a terminology system to obtain the semantic events of the formatted entries; The semantic events are aligned with their spatiotemporal source identifiers to obtain the spatiotemporal reference events of the semantic events; Based on a preset unified event paradigm, the load structure of the spatiotemporal reference events is reorganized to obtain standardized events of the multi-source heterogeneous logs.

[0007] In a preferred embodiment, the step of performing time-series dependency mining on the standardized events to obtain the potential threat patterns of the standardized events includes: Invariant dependency topology discovery is performed on the normalized events to obtain the temporal dependency graph of the normalized events; The temporal dependency graph is subjected to multi-dimensional quantitative evaluation to obtain the high-value threat paths of the temporal dependency graph. The confidence level of the high-value threat path is calibrated, and the path after calibration is logically reconstructed to obtain the behavioral constraint rules of the high-value threat path. The behavioral constraint rules are formally encapsulated to obtain the potential threat patterns of the standardized events.

[0008] In a preferred embodiment, the step of performing multi-dimensional quantitative evaluation of the temporal dependency graph to obtain high-value threat paths in the temporal dependency graph includes: Anomaly propagation analysis is performed on the temporal dependency graph to obtain the threat paths of the temporal dependency graph; The hazard of the threat path is measured to obtain the destructive intensity of the threat path; Based on the damage intensity, the threat path is attenuated to obtain the attenuation coefficient of the threat path; Based on the damage intensity and the attenuation coefficient, a comprehensive threat score for the threat path is calculated, wherein the formula for calculating the comprehensive threat score is: ; In the formula, For the comprehensive threat score, The number of events in the threat path. For the threat path, the first The destructive intensity of the event, It is a natural exponential function. For the threat path, the first The decay coefficient of an event. This is a preset environmental observability adjustment factor. It is the natural logarithm function. The standard deviation of the destructive intensity of all events in the threat path is given. This represents the average destructive intensity of all events along the threat path. Based on the comprehensive threat score, the threat paths are adaptively thresholded to obtain the high-value threat paths in the time-series dependency graph.

[0009] In a preferred embodiment, the step of actively traversing and matching the standardized events based on the potential threat pattern to obtain a candidate associated event sequence of the standardized events includes: Predictive operational encoding is performed on the potential threat pattern to obtain the detection command for the potential threat pattern; Based on the exploration command, the standardized events are retrieved in parallel to obtain the matching events of the standardized events; The matching events are further refined through feedback analysis to obtain a concise association between them. Based on the refined association, the standardized events are arranged according to temporal logic to obtain a sequence of candidate associated events for the standardized events.

[0010] In a preferred embodiment, the step of reverse-engineering the subsequent evolution stages of the target network environment based on the candidate associated event sequence to obtain the verification probe strategy for the subsequent evolution stages includes: Dynamic behavior slicing is performed on the candidate associated event sequence to obtain the behavior stage segment of the candidate associated event sequence; Logical completeness analysis is performed on the behavioral stage segment to obtain the logically unclosed interval of the behavioral stage segment; Based on the logically unclosed interval, the state transition path is deduced for the subsequent evolution stage of the target network environment to obtain the subsequent action sequence of the subsequent evolution stage; The subsequent action sequence is visualized and integrated to obtain the verification probe strategy for the subsequent evolution stage.

[0011] In a preferred embodiment, the step of performing state transition path deduction for the subsequent evolution stages of the target network environment based on the logically unclosed interval to obtain the subsequent action sequence of the subsequent evolution stages includes: The policy profile is parsed for the logically unclosed intervals to obtain the intent description and observable tactical fingerprint of the logically unclosed intervals; Based on the observable tactical fingerprint, the dynamic protection effectiveness of the target network environment is evaluated to obtain the real-time defense resilience of the target network environment. Based on the intent description and the real-time defense resilience, attack path planning is performed on the logically unclosed interval to obtain the candidate action chain of the logically unclosed interval. Calculate the comprehensive opportunity index of the candidate action chain, wherein the formula for calculating the comprehensive opportunity index is: ; In the formula, The comprehensive opportunistic index is referred to here. At the starting time, The length of the time window. The preset time-varying decision preference coefficients, It is the natural logarithm function. For the candidate action chain at time... The expected progress contribution For the preset smallest positive number, As a preset time-varying factor of risk aversion, For the candidate action chain at time... Instantaneous risk exposure The cutoff time of the candidate action chain The cumulative operational feature entropy; Based on the comprehensive opportunistic index, the candidate action chain is globally optimized, and the steps of the optimized action chain are decoupled to obtain the subsequent action sequence of the subsequent evolution stage.

[0012] In a preferred embodiment, applying the verification probe strategy to the target network environment and incrementally collecting data from the target network environment to obtain verification feedback data for the target network environment includes: The verification probe strategy is encapsulated into an executable form to obtain a deployable probe instance of the verification probe strategy; Based on the deployable probe instance, induced behavior is triggered in the target network environment to obtain the behavioral trajectory of the target network environment. Based on the behavioral trajectory, a controlled perturbation is injected into the interaction state of the target network environment to obtain the perturbation-post-state information of the target network environment. Based on the post-disturbance state information and the behavioral trajectory, targeted evidence collection is performed on the target network environment to obtain verification feedback data of the target network environment.

[0013] In a preferred embodiment, the step of assessing the threat level of the candidate associated event sequences based on the verification feedback data to obtain an analysis report of the target network environment includes: The verification feedback data is effectively discriminated and characterized to obtain the effective features of the verification feedback data; Based on the aforementioned effective features, multidimensional threat quantification is performed on the candidate associated event sequence to obtain the threat index of the candidate associated event sequence; The threat indicators are weighted and fused according to confidence level to obtain the fused threat index. Based on the fusion threat index, abnormal patterns are summarized in the candidate associated event sequences to obtain an assessment report of the target network environment.

[0014] To address the aforementioned problems, this invention also provides a log correlation analysis system for abnormal network operation behavior, the system comprising: The log normalization parsing module is used to perform normalization element parsing on multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous log stream. The temporal dependency mining module is used to perform temporal dependency mining on the standardized events to obtain the potential threat patterns of the standardized events. An active traversal matching module is used to actively traverse and match the standardized events based on the potential threat pattern to obtain a candidate associated event sequence of the standardized events. The reverse deduction verification module is used to reverse deduce the subsequent evolution stages of the target network environment based on the candidate associated event sequence, and obtain the verification probe strategy for the subsequent evolution stages. An incremental verification acquisition module is used to apply the verification probe strategy to the target network environment and perform incremental data acquisition on the target network environment to obtain verification feedback data of the target network environment. The threat assessment and analysis module is used to assess the threat level of the candidate related event sequence based on the verification feedback data, and obtain an analysis report of the target network environment.

[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention achieves accurate extraction and unified representation of standardized events by performing normalized element analysis on multi-source heterogeneous logs. Combined with invariant dependency topology discovery and multi-dimensional quantitative evaluation technology, it efficiently mines potential threat patterns of standardized events, greatly improving the completeness and accuracy of threat path identification, and providing a high-quality data foundation and core basis for network anomaly behavior analysis.

[0016] 2. Based on the verification probe strategy generated by active traversal matching and reverse inference, and combined with the threat assessment mechanism of incremental data collection and confidence-weighted fusion, this invention realizes dynamic verification and accurate quantification of candidate related event sequences, significantly improves the overall efficiency of log correlation analysis, and enhances the scientificity and credibility of the assessment report, providing reliable support for network security protection decisions. Attached Figure Description

[0017] Figure 1 This is a flowchart illustrating a method for log correlation analysis of abnormal network operation behavior according to an embodiment of the present invention. Figure 2 This is a functional module diagram of a log correlation analysis system for abnormal network operation behavior provided in an embodiment of the present invention; The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0018] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0019] This application provides a method for log correlation analysis of abnormal network operation behavior. The executing entity of this method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. In other words, the method for log correlation analysis of abnormal network operation behavior can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0020] Reference Figure 1The diagram shown is a flowchart illustrating a method for log correlation analysis of abnormal network operation behavior according to an embodiment of the present invention. In this embodiment, the method for log correlation analysis of abnormal network operation behavior includes: S01. Normalize the elements of the multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous logs. In this embodiment of the invention, the step of normalizing the elements of multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous logs includes: A general format adaptation is performed on the multi-source heterogeneous logs of the target network environment to obtain formatted entries for the target network environment; The formatted entries are summarized using a terminology system to obtain the semantic events of the formatted entries; The semantic events are aligned with their spatiotemporal source identifiers to obtain the spatiotemporal reference events of the semantic events; Based on a preset unified event paradigm, the load structure of the spatiotemporal reference events is reorganized to obtain standardized events of the multi-source heterogeneous logs.

[0021] This process collects multi-source heterogeneous logs from all sources within the target network environment, covering various log data generated by different devices, applications, and services. These logs may have different field definitions, data formats, and representation methods. For each type of log, the core information elements are systematically analyzed to determine a common set of core fields. Field names and data type standards are standardized; for example, the time field in all types of logs is standardized as "Event Occurrence Time" with a fixed date and time format, and the device identifier field is standardized as "Source Device" with standardized encoding rules. Meaningless spaces, special symbols, and redundant field content are removed from the logs, ensuring that all log data follows the same structural specifications and format requirements, ultimately forming formatted entries with unified fields, standardized formats, and complete information.

[0022] This process involves analyzing all descriptions related to operational behaviors, system states, and data objects within the formatted entries, establishing a comprehensive terminology mapping list. Terms with the same meaning but different expressions are standardized and unified. For example, different expressions such as "account login failed," "login verification failed," and "failed to log in successfully" are uniformly defined as "account login abnormality," and "data transmission interrupted," "transmission connection disconnected," and "data transmission failed" are uniformly defined as "data transmission abnormality." Based on this unified terminology system, each formatted entry is analyzed in depth to clarify the core event essence described by the entry, extracting key semantic information such as the event's subject, action, triggering conditions, and result status. This transforms the originally formatted entries, which only possessed uniform formatting, into semantic events that clearly and accurately express the core meaning of the event.

[0023] The implicit time and source information is extracted from each semantic event. Time information includes the specific time of occurrence and duration of the event, while source information includes the device model, system name, network address, and user account from which the event occurred. Using a common standard time base as a reference, time information from different time zones and formats is converted into a unified standard time format, ensuring consistency and comparability of time records for all events. Simultaneously, source information is standardized by assigning a unique identifier code to each event source, clarifying source hierarchy, and eliminating multiple expressions for the same source. This ensures that all semantic events have a unified reference benchmark in both the time and source dimensions, resulting in spatiotemporal benchmark events with clear spatiotemporal attributes and unified source identification.

[0024] The pre-defined unified event paradigm includes fixed core fields such as a unique event identifier, event classification type, standard occurrence time, standard source identifier, core event description, and related event index, clearly defining the definition, value range, and expression standard of each field. For each spatiotemporal benchmark event, the corresponding information is extracted from the spatiotemporal benchmark event one by one according to the field requirements of the unified event paradigm. The core content of the event is reorganized and filled according to the field logic specified by the paradigm, supplementing necessary related information and eliminating redundant content irrelevant to the paradigm. This ensures that the payload structure of each event fully conforms to the requirements of the unified event paradigm, with complete fields, clear logic, and standardized expression, ultimately forming a standardized event with a unified structure and unified standard that can be directly used for subsequent analysis and processing.

[0025] The beneficial effects include the ability to perform standardized element analysis on multi-source heterogeneous logs of the target network environment, accurately transforming them into standardized events. Then, through time-series dependency mining, potential threat patterns are precisely captured, and high-value threat paths are efficiently screened, laying a solid foundation for subsequent analysis. Active traversal matching based on potential threat patterns can quickly obtain candidate related event sequences. Combined with reverse inference, targeted verification probe strategies are generated, and accurate verification feedback data is obtained through incremental data collection. Based on the feedback data, multi-dimensional threat quantification and confidence-weighted fusion can accurately assess the threat level of candidate related event sequences, summarize anomaly patterns to form reliable judgment reports, and comprehensively improve the systematicness and effectiveness of network anomaly operation behavior log correlation analysis, providing scientific and accurate support for network security protection decisions.

[0026] S02. Perform time-series dependency mining on the standardized events to obtain the potential threat patterns of the standardized events; In this embodiment of the invention, the step of performing time-series dependency mining on the standardized events to obtain the potential threat patterns of the standardized events includes: Invariant dependency topology discovery is performed on the normalized events to obtain the temporal dependency graph of the normalized events; The temporal dependency graph is subjected to multi-dimensional quantitative evaluation to obtain the high-value threat paths of the temporal dependency graph. The confidence level of the high-value threat path is calibrated, and the path after calibration is logically reconstructed to obtain the behavioral constraint rules of the high-value threat path. The behavioral constraint rules are formally encapsulated to obtain the potential threat patterns of the standardized events.

[0027] The step of performing multi-dimensional quantitative evaluation of the temporal dependency graph to obtain high-value threat paths in the temporal dependency graph includes: Anomaly propagation analysis is performed on the temporal dependency graph to obtain the threat paths of the temporal dependency graph; The hazard of the threat path is measured to obtain the destructive intensity of the threat path; Based on the damage intensity, the threat path is attenuated to obtain the attenuation coefficient of the threat path; Based on the damage intensity and the attenuation coefficient, a comprehensive threat score for the threat path is calculated, wherein the formula for calculating the comprehensive threat score is: ; In the formula, For the comprehensive threat score, The number of events in the threat path. For the threat path, the first The destructive intensity of the event, It is a natural exponential function. For the threat path, the first The decay coefficient of an event. This is a preset environmental observability adjustment factor. It is the natural logarithm function. The standard deviation of the destructive intensity of all events in the threat path is given. This represents the average destructive intensity of all events along the threat path. Based on the comprehensive threat score, the threat paths are adaptively thresholded to obtain the high-value threat paths in the time-series dependency graph.

[0028] By analyzing the order of occurrence and interrelationships of all standardized events, identifying stable dependencies between events that are unaffected by temporary fluctuations, clarifying the sequential connection logic and causal relationships of different events in the time dimension, presenting these unchanging dependencies in a visual link form, clearly marking the position of each standardized event and the type of association between events, and finally forming a temporal dependency map that can fully reflect the temporal dependencies of events.

[0029] By filtering out nodes and links that deviate from normal association logic from the temporal dependency graph, tracing the path of these abnormal nodes spreading to other nodes through existing dependencies, and following the trajectory of abnormal propagation, a continuous chain composed of a series of related abnormal events is identified. This continuous chain of abnormal events is the threat path of the temporal dependency graph.

[0030] For each threat path, the impact range, degree of functional abnormality, and harmful consequences on network security of each event in the path are analyzed one by one. Combining factors such as the importance of the network resources affected by the event and the directness of the destructive behavior, the overall harm level of each threat path is comprehensively measured, and finally the destructive intensity that can characterize the harm level of each threat path is formed.

[0031] Based on the destructive intensity of the threat path, combined with the time interval between events in the path, the degree of correlation between events, and the network environment's own protection mechanism's ability to block threats and its self-recovery capability, the weakening of the threat path's impact over time is analyzed. This weakening degree is represented by a specific characterization value, which is the threat path attenuation coefficient.

[0032] By combining the destructive intensity of each event in each threat path with its corresponding attenuation coefficient, taking into account the observability of threats in the current network environment, comprehensively considering the overall distribution characteristics of the destructive intensity of all events, balancing the impact of the magnitude of the destructive intensity and the attenuation coefficient, a comprehensive and integrated assessment of the overall threat level of each threat path is conducted, ultimately resulting in a comprehensive threat score that can uniformly reflect the threat level of the path.

[0033] Collect comprehensive threat scores for all threat paths, analyze the distribution range and concentration trend of these scores, and set a realistic screening threshold based on the security requirements and protection standards of the current target network environment. Select threat paths whose comprehensive threat scores reach or exceed the threshold. These selected paths are the high-value threat paths in the time-dependent graph.

[0034] Each high-value threat path is compared with historically known real threat paths to verify the rationality and authenticity of the connections between events in the path. Unreliable connections are removed, and the path's credibility is adjusted to ensure it accurately reflects the threat evolution logic. Based on this, the calibrated paths are re-examined according to chronological order and logical relationships, clarifying the chronological conditions, triggering prerequisites, and mutual constraints of events within the path. These clarified logical relationships are then organized into clear and rigorous rules, forming behavioral constraint rules for high-value threat paths.

[0035] By adopting a unified and standardized expression method, the core elements of behavioral constraint rules, such as triggering conditions, event association logic, and constraint boundaries, are clearly defined. Redundant and ambiguous expressions in the rules are removed, so that each rule has a unified structure, clear semantics, and a directly interpretable format, forming a standardized set of rules. Ultimately, this yields a potential threat pattern that accurately reflects the threat characteristics of standardized events.

[0036] The number of events in a threat path is obtained directly by statistically analyzing the total number of events contained in a single threat path. The destructive intensity of each event is obtained by comprehensively measuring the harm of each event in the threat path. The attenuation coefficient of each event is obtained by attenuating based on the destructive intensity of the corresponding event, combined with the propagation characteristics of the threat path and the protection effect of the network environment. The environmental observability adjustment factor is a fixed value pre-set according to the actual observation conditions of the target network environment. The standard deviation of the destructive intensity of all events is obtained by summing the deviations of the destructive intensity of each event from the mean. The mean of the destructive intensity of all events is obtained by calculating the average level of the destructive intensity of all events in the threat path.

[0037] The significance of this formula lies in comprehensively considering the actual harm level of each event in the threat path, the weakening of the threat over time and during the propagation process, the observability of the network environment for the threat, and the discrete distribution characteristics of the destructive intensity of all events. Through systematic integration and calculation, a unified score that can comprehensively and accurately reflect the overall threat level of a single threat path is obtained, providing a clear and reliable basis for subsequent screening of high-value threat paths.

[0038] The higher the destructive intensity of each event, the greater its positive contribution to the overall score. The higher the attenuation coefficient of each event, the more significantly its corresponding destructive intensity is weakened in the calculation, and the lower the overall score. When the environmental observability adjustment factor is fixed, the attenuation coefficient's weakening effect on the destructive intensity changes according to a fixed pattern. The higher the ratio of the standard deviation of the destructive intensity of all events to the mean, the greater the dispersion of the destructive intensity distribution, and the more significant the positive contribution to the overall score, ultimately driving the overall score to show corresponding changes.

[0039] The beneficial effects include the ability to perform standardized element analysis on multi-source heterogeneous logs of the target network environment, accurately acquire standardized events, and effectively identify potential threat patterns through time-series dependency mining. Based on these patterns, proactive traversal matching can quickly generate candidate related event sequences. Reverse deduction based on these candidate related event sequences can generate targeted verification probe strategies for subsequent evolution stages. Applying these strategies to the target network environment and conducting incremental data collection yields accurate verification feedback data. Combining the verification feedback data with a comprehensive threat level assessment of the candidate related event sequences allows for the summarization of anomaly patterns and the generation of reliable analysis reports. This comprehensively improves the systematicness and accuracy of network anomaly behavior log correlation analysis, providing strong support for network security protection decisions.

[0040] This system can perform standardized element analysis on multi-source heterogeneous logs from target network environments, accurately acquire standardized events, and then effectively capture potential threat patterns of these standardized events through time-series dependency mining. Based on these patterns, proactive traversal matching can quickly generate candidate related event sequences. Reverse deduction based on these candidate related event sequences can generate verification probe strategies adapted to subsequent evolution stages. Applying these strategies to the target network environment and implementing incremental data collection yields accurate verification feedback data. Combining the verification feedback data with a comprehensive threat level assessment of the candidate related event sequences allows for the summarization of anomaly patterns and the generation of reliable analysis reports. This ensures the systematic nature and accuracy of log correlation analysis throughout the process, providing scientific and powerful support for network security protection decisions and significantly improving the overall effectiveness of network anomaly behavior log correlation analysis.

[0041] S03. Based on the potential threat pattern, actively traverse and match the standardized events to obtain a candidate associated event sequence of the standardized events; In this embodiment of the invention, the step of actively traversing and matching the standardized events based on the potential threat pattern to obtain a candidate associated event sequence of the standardized events includes: Predictive operational encoding is performed on the potential threat pattern to obtain the detection command for the potential threat pattern; Based on the exploration command, the standardized events are retrieved in parallel to obtain the matching events of the standardized events; The matching events are further refined through feedback analysis to obtain a concise association between them. Based on the refined association, the standardized events are arranged according to temporal logic to obtain a sequence of candidate associated events for the standardized events.

[0042] This process involves analyzing the behavioral constraints, threat characteristics, and event correlation logic of potential threat patterns. Each core element is broken down into specific search targets and operational requirements, transforming abstract threat characteristics into concrete and clearly executable instructions. For the triggering conditions within the patterns, the types of events to be searched, key attributes, and fulfilled state requirements are clearly defined. For the event correlation logic, the temporal relationships, causal relationships, and constraint boundaries between events are defined. For the threat evolution path, the directions and characteristics of subsequent possible events to be explored are identified. These specific requirements are then standardized according to a unified instruction format, with each instruction corresponding to a clear search target. This ensures that the instructions are clearly articulated, precisely targeted, and directly usable to guide standardized event search operations, ultimately forming the search instructions for potential threat patterns.

[0043] Based on the different search conditions and objectives in the exploration instructions, the standardized event dataset is divided into multiple independent search units, each corresponding to a core exploration objective, ensuring that the search tasks of each unit do not interfere with each other. Simultaneously, the search operations of all search units are initiated. For each standardized event within a unit, key information such as event classification type, core event description, standard occurrence time, and standard source identifier are extracted one by one and compared with the corresponding exploration instruction conditions to check whether the event information fully meets the instruction requirements. All standardized events that meet the instruction conditions are fully extracted, and the extraction results of all search units are summarized. Duplicate event entries are removed to form a list of matching events containing all events that meet the exploration requirements.

[0044] Collect all matching events and their original association information, and verify each matching event's association logic with other matching events against the behavioral constraint rules in the potential threat pattern. Events with inconsistent association logic are directly removed from the matching event set. For events with incomplete association information, corresponding related events are found to complete the association chain. A thorough analysis of the causal and dependency relationships among the retained matching events is conducted to clarify the role and function of each event in the threat evolution process. The temporal connection and logical association between events are strengthened, eliminating ambiguous or logically broken associations. This results in a logically rigorous, closely related association set that conforms to the characteristics of the potential threat pattern—a refined association set of matching events.

[0045] The standard occurrence times of all events in the refined correlation are extracted, and these events are initially arranged in chronological order to form a basic event sequence. Based on the behavioral constraints and event association logic in the potential threat model, the basic event sequence is meticulously adjusted, clarifying the preceding and subsequent triggering events for each event, ensuring that the order of events perfectly matches the logical progression of threat evolution. The sequence is checked for any temporal inconsistencies or logical contradictions; illogical event sequences are corrected, and missing key transitional events are added to ensure the entire event sequence fully and coherently reflects the evolutionary path of the potential threat. Finally, a candidate correlation event sequence of standardized events is formed, characterized by a reasonable order, clear logic, close correlation, and complete adherence to the features of the refined correlation.

[0046] The beneficial effects include the ability to transform potential threat patterns into precise detection commands, enabling efficient parallel retrieval of standardized events and quickly identifying matching events that meet the requirements, significantly reducing the time spent on ineffective searches. Deep feedback on matching events strengthens the logical connections between events, eliminating irrelevant or loosely related content to form logically rigorous and refined associations, ensuring the accuracy and effectiveness of the associated information. Based on these refined associations, a scientific temporal logical arrangement is implemented to clarify the sequence and causal relationships of events, constructing a complete and coherent sequence of candidate related events. This provides a high-quality analytical foundation for subsequent threat verification and assessment, comprehensively improving the efficiency and accuracy of correlation analysis of network anomaly behavior logs, and providing solid support for network security protection decisions.

[0047] S04. Based on the candidate associated event sequence, reverse the evolution of the target network environment to obtain the verification probe strategy for the subsequent evolution stage. In this embodiment of the invention, the step of reverse-engineering the subsequent evolution stages of the target network environment based on the candidate associated event sequence to obtain the verification probe strategy for the subsequent evolution stages includes: Dynamic behavior slicing is performed on the candidate associated event sequence to obtain the behavior stage segment of the candidate associated event sequence; Logical completeness analysis is performed on the behavioral stage segment to obtain the logically unclosed interval of the behavioral stage segment; Based on the logically unclosed interval, the state transition path is deduced for the subsequent evolution stage of the target network environment to obtain the subsequent action sequence of the subsequent evolution stage; The subsequent action sequence is visualized and integrated to obtain the verification probe strategy for the subsequent evolution stage.

[0048] Based on the logically unclosed interval, the state transition path is deduced for the subsequent evolution stages of the target network environment to obtain the subsequent action sequence for the subsequent evolution stages, including: The policy profile is parsed for the logically unclosed intervals to obtain the intent description and observable tactical fingerprint of the logically unclosed intervals; Based on the observable tactical fingerprint, the dynamic protection effectiveness of the target network environment is evaluated to obtain the real-time defense resilience of the target network environment. Based on the intent description and the real-time defense resilience, attack path planning is performed on the logically unclosed interval to obtain the candidate action chain of the logically unclosed interval. Calculate the comprehensive opportunity index of the candidate action chain, wherein the formula for calculating the comprehensive opportunity index is: ; In the formula, The comprehensive opportunistic index is referred to here. At the starting time, The length of the time window. The preset time-varying decision preference coefficients, It is the natural logarithm function. For the candidate action chain at time... The expected progress contribution For the preset smallest positive number, As a preset time-varying factor of risk aversion, For the candidate action chain at time... Instantaneous risk exposure The cutoff time of the candidate action chain The cumulative operational feature entropy; Based on the comprehensive opportunistic index, the candidate action chain is globally optimized, and the steps of the optimized action chain are decoupled to obtain the subsequent action sequence of the subsequent evolution stage.

[0049] By analyzing the behavioral attributes, occurrence time, and logical connections of all events in the candidate related event sequence, and based on the functional purpose of the events, natural time intervals, and the tightness of the connections between events, the entire candidate related event sequence is divided into multiple independent segments. Each segment focuses on a specific behavioral theme and contains a set of logically coherent and relatively concentrated events around that theme, ensuring smooth transitions between events within a segment and clear boundaries between segments, ultimately forming the behavioral stage segments of the candidate related event sequence.

[0050] Analyze the causal relationships, logical deduction chains, and state transition processes of each behavioral stage segment, checking whether the entire behavioral flow from the starting event to the ending event forms a complete closed loop. Compare with the preset logical completeness standards to identify any missing prerequisite events, broken logical transition links, or unachieved state goals. Clearly identify the specific intervals in each segment that fail to complete the logical closed loop or have deduction gaps; these intervals with logical gaps are the logically unclosed intervals of the behavioral stage segment.

[0051] By deeply analyzing the behavioral characteristics, correlation patterns, and incomplete logical steps of events that have occurred within the logically unclosed interval, the core objectives and potential intentions of the events within this interval are extracted, forming a clear and explicit description of the intentions. Simultaneously, the externally identifiable behavioral traces presented by the events within this interval, such as operational methods, triggering conditions, characteristic identifiers, and execution paths, are summarized and integrated to form an observable tactical fingerprint.

[0052] Using observable tactical fingerprints as a benchmark, a comprehensive review of the protective measures against such tactical fingerprints in the target network environment is conducted, including security policy configuration, deployment of protective equipment, monitoring and early warning mechanisms, and emergency response procedures. The identification capability, interception effectiveness, response speed, and self-recovery capability of each protective measure against the behaviors characterized by observable tactical fingerprints are analyzed, along with the network environment's overall ability to withstand such potential threats. This comprehensive assessment forms a real-time defense resilience system that accurately reflects the current level of network protection.

[0053] Based on the core objectives clearly stated in the intent description and referencing the network protection weaknesses and strengths revealed by real-time defense resilience, multiple continuous action paths are planned to fill logical gaps and achieve the core objectives. Each path's actions are specifically designed to avoid network protection strengths, fully utilize protection weaknesses, and ensure seamless and logical connections between actions, completely covering the logical gaps in the unclosed intervals. These planned continuous action paths constitute the candidate action chains for logically unclosed intervals.

[0054] This study comprehensively considers the start time and available timeframe of each candidate action chain, analyzes the contribution of each action in the chain to achieving the core objective, assesses the types of risks, probability of occurrence, and scope of impact during action execution, and also focuses on the continuity of the action chain, the dependencies between actions, and the cumulative changes in behavioral characteristics. Through a comprehensive weighing of these factors, the overall value and suitability of each candidate action chain are comprehensively measured, resulting in a comprehensive timing index that reflects its execution value.

[0055] By comparing the comprehensive opportunity index of all candidate action chains horizontally, the action chain with the highest comprehensive opportunity index that best meets the expected requirements is selected as the globally optimal action chain. According to the chronological order of events in the action chain, the optimal action chain is broken down into a series of independent individual steps with clearly defined execution requirements. Each step clearly defines its execution content, triggering conditions, operation object, expected result, and execution priority, ensuring that each step is independently executable. These sequentially arranged independent steps together constitute the subsequent action sequence for the subsequent evolution stages.

[0056] Each independent step in the subsequent action sequence is transformed into a specific, implementable probe operation instruction, clearly defining the execution target, operation method, execution sequence, monitoring indicators, data collection scope, and storage format for each instruction. All instructions are systematically integrated, clarifying the execution logic and dependencies between them, supplementing necessary execution instructions and exception handling mechanisms, forming a complete, logically clear, and operationally standardized verification probe strategy that can be directly deployed to the target network environment. This ensures that the strategy can accurately capture the development of events in subsequent evolution stages.

[0057] The start time is the predetermined point in time when the candidate action chain begins execution, directly determined by the planned starting node of the action chain. The time window length is a fixed time span pre-set based on the monitoring cycle requirements of the target network environment and the expected execution duration of the candidate action chain. The time-varying decision preference coefficient is a pre-set, adjustable value that adapts to the changing security needs of the target network environment. The expected progress contribution is derived by analyzing the actual assistance provided by the candidate action chain at each execution time in filling logically unclosed intervals and achieving the core objectives described in the intent description. The minimum normal number is a fixed, small value pre-set to avoid meaningless numerical results during calculation. The risk aversion time-varying factor is a dynamically set adjustment factor that changes over time based on the current target network environment's tolerance to various risks. The instantaneous risk exposure is a risk characterization value derived by comprehensively assessing the types of risks, probabilities of occurrence, and the scope of impact that the candidate action chain may face during each execution time. The cumulative operational characteristic entropy is derived by statistically analyzing the diversity and disorder of the behavioral characteristics exhibited by the executed steps of the candidate action chain up to each time point.

[0058] The significance of this formula lies in comprehensively considering the expected progress contribution, instantaneous risk status, dynamic decision preferences, and cumulative behavioral characteristics of candidate action chains within a set time window. Through systematic integration and analysis, it comprehensively measures the execution value and suitability of each candidate action chain, providing a unified and reliable basis for the selection of the global optimal action chain, and ensuring that the selected action chain can efficiently fill the logically unclosed interval.

[0059] When the time-varying decision preference coefficient adjusts towards emphasizing progress contribution, the increase in expected progress contribution will positively impact the final outcome, while an increase in instantaneous risk exposure will weaken this positive effect. When the time-varying risk aversion factor adjusts towards strengthening risk avoidance, an increase in instantaneous risk exposure will have a negative inhibitory effect on the final outcome. An increase in cumulative operational entropy will directly have a negative impact on the final outcome, while an increase in expected progress contribution will mitigate the degree of this negative impact. The dynamic changes of all relevant factors work together to determine the direction of change in the final outcome.

[0060] The beneficial effects include the ability to perform standardized element analysis on multi-source heterogeneous logs of the target network environment, accurately obtain standardized events, effectively capture potential threat patterns through time-series dependency mining, and rapidly form logically rigorous candidate related event sequences through proactive traversal matching based on these patterns. Based on the candidate related event sequences, a targeted verification probe strategy is generated through reverse deduction. Applying this strategy and conducting incremental data collection yields accurate verification feedback data. Combining the feedback data with multi-dimensional threat quantification and confidence-weighted fusion of the candidate related event sequences accurately assesses the threat level and summarizes abnormal patterns, generating reliable analysis reports. This ensures the systematic nature and accuracy of log correlation analysis throughout the process, effectively improving the overall efficiency of network anomaly behavior log correlation analysis and providing strong scientific support for network security protection decisions.

[0061] This system can perform standardized element analysis on multi-source heterogeneous logs of the target network environment, accurately acquire standardized events, effectively capture potential threat patterns through time-series dependency mining, and rapidly form logically rigorous candidate related event sequences through proactive traversal matching based on these patterns. Based on the candidate related event sequences, targeted verification probe strategies are generated through reverse deduction. Applying these strategies to the target network environment and conducting incremental data collection yields accurate verification feedback data. Combining the feedback data with multi-dimensional threat quantification and confidence-weighted fusion of the candidate related event sequences accurately assesses the threat level and summarizes abnormal patterns, generating reliable analysis reports. This comprehensively improves the systematicness, accuracy, and efficiency of network anomaly behavior log correlation analysis, providing strong scientific support for network security protection decisions.

[0062] S05. Apply the verification probe strategy to the target network environment and perform incremental data collection on the target network environment to obtain verification feedback data of the target network environment. In this embodiment of the invention, applying the verification probe strategy to the target network environment and incrementally collecting data from the target network environment to obtain verification feedback data of the target network environment includes: The verification probe strategy is encapsulated into an executable form to obtain a deployable probe instance of the verification probe strategy; Based on the deployable probe instance, induced behavior is triggered in the target network environment to obtain the behavioral trajectory of the target network environment. Based on the behavioral trajectory, a controlled perturbation is injected into the interaction state of the target network environment to obtain the perturbation-post-state information of the target network environment. Based on the post-disturbance state information and the behavioral trajectory, targeted evidence collection is performed on the target network environment to obtain verification feedback data of the target network environment.

[0063] This process involves analyzing and verifying all operational instructions, execution sequences, monitoring metrics, and data collection requirements within the probe strategy, transforming abstract strategy content into concrete, executable operational procedures. A standardized instruction format is established, clearly defining the execution target, operation method, triggering conditions, and expected results for each operation. An environment adaptation module is added to the strategy to ensure compatibility with the target network environment's network protocols, interface specifications, and access control requirements. Exception handling logic is supplemented, establishing fixed retry mechanisms and termination conditions for potential connection interruptions, response timeouts, and other issues during execution. An operation log recording function is also added to record key node information during probe execution in real time, ultimately forming a complete, deployable probe instance that can be directly started and run in the target network environment.

[0064] Deployable probe instances are deployed to key interactive nodes in the target network environment. These nodes cover the core data transmission path, application service interface endpoints, and network device communication ports. Following the preset timing and triggering conditions in the probe instances, specific stimulus signals are sent to relevant components in the target network environment. These signals include request commands simulating normal business operations, interactive data conforming to potential threat characteristics, and wake-up commands triggering specific functions. The response behavior of each component in the target network environment to these stimulus signals is continuously monitored. The occurrence time, execution process, data flow path, and component state changes of each response are fully recorded. These continuous records are integrated chronologically to form a behavioral trajectory that fully reflects the network environment's behavioral response process.

[0065] A thorough analysis of the behavioral trajectory is conducted to identify key interaction nodes, data flow logic, and component collaboration patterns, clarifying the current interaction state characteristics of the network environment. Specific perturbation methods are designed based on verification requirements. These perturbation methods include slightly adjusting the timing interval of data interactions, changing the sending frequency of request commands, and adjusting some non-core fields of data packets. All perturbations are controlled within a range that does not affect the normal operation of the target network environment, ensuring the controllability and security of the perturbations. These pre-set perturbations are injected into key interaction links in the behavioral trajectory. The response status of each component, data processing results, changes in interaction relationships, and system resource usage after the perturbations are monitored and recorded in real time. These records are then comprehensively summarized to form the post-perturbation state information.

[0066] By combining post-disruption state information and behavioral trajectories, the types of evidence to be collected are identified. This evidence includes records of component state changes related to potential threat patterns, traces of abnormal data interactions, differences in log generation content, and response behaviors. For each type of evidence, the specific collection scope and methods are determined. Key information related to post-disruption state changes and behavioral trajectories is extracted from server logs, application runtime records, network traffic data, and component status reports in the target network environment. The extracted information is then filtered to remove redundant content irrelevant to the verification objective. The completeness and accuracy of the information are verified, and the filtered information is categorized and organized according to evidence type, occurrence time, and associated components to form clearly structured, complete verification feedback data that can directly support subsequent verification analysis.

[0067] The beneficial effects include the ability to transform verification probe strategies into directly deployable probe instances, ensuring stable execution of the strategies in the target network environment. Through induced behavior triggers, it accurately captures the real behavioral trajectories of the network environment, fully presenting the event response process and data flow logic. By leveraging controlled perturbation injection without affecting normal network operation, it obtains post-perturbation state information, comprehensively mining the behavioral characteristics and response patterns of the network environment under dynamic changes. Combined with behavioral trajectories and post-perturbation state information, it conducts targeted evidence collection, screening and integrating key information highly relevant to the verification target, forming complete, accurate, and highly valuable verification feedback data. This provides solid data support for the verification and threat assessment of candidate related event sequences, improves the accuracy and reliability of network anomaly behavior log correlation analysis, and provides comprehensive and effective data basis for network security protection decisions.

[0068] S06. Based on the verification feedback data, assess the threat level of the candidate associated event sequence to obtain an analysis report of the target network environment; In this embodiment of the invention, the step of assessing the threat level of the candidate associated event sequence based on the verification feedback data to obtain an analysis report of the target network environment includes: The verification feedback data is effectively discriminated and characterized to obtain the effective features of the verification feedback data; Based on the aforementioned effective features, multidimensional threat quantification is performed on the candidate associated event sequence to obtain the threat index of the candidate associated event sequence; The threat indicators are weighted and fused according to confidence level to obtain the fused threat index. Based on the fusion threat index, abnormal patterns are summarized in the candidate associated event sequences to obtain an assessment report of the target network environment.

[0069] The verification feedback data is analyzed and processed, including behavioral trajectories, post-disturbance state information, and targeted evidence. The data source attributes, recording dimensions, and associated objects are clarified, and redundant information and duplicate records unrelated to the candidate associated event sequences are removed. For the remaining data, core information relevant to threat assessment is extracted, including the scope of components affected by the event, the specific types of state changes, abnormal traces of data interaction, and the time intervals between events. This core information is standardized in description, with unified expression formats and classification standards, forming effective features that accurately reflect threat-related attributes. This ensures that each effective feature corresponds to key threat-related information in the verification feedback data.

[0070] Based on the threat-related attributes covered by the effective features, a multi-dimensional threat assessment dimension is determined, including impact scope, degree of damage, propagation path integrity, recovery difficulty, and interaction anomaly intensity. For each assessment dimension, targeted quantification is performed based on specific information in the effective features. The impact scope dimension determines specific characterization values ​​by referring to the number of affected components and the coverage of data flow; the degree of damage dimension sets corresponding results based on the severity level of component state anomalies and the specific circumstances of data corruption or leakage; the propagation path integrity dimension is defined based on the continuity of event associations and the number of key nodes covered by the path; the recovery difficulty dimension quantifies the results according to the operational steps required for state recovery and the scale of resource investment; the interaction anomaly intensity dimension is judged by combining the degree of deviation of data interaction from normal standards and the frequency of anomaly occurrence. The quantification results of each dimension together constitute the threat indicators of the candidate associated event sequence.

[0071] Each threat indicator was verified for the reliability of its source, the completeness of its records, and the accuracy of its information. Based on the verification results, the confidence level of each threat indicator was determined. Indicators with standardized data collection processes, complete records, and authoritative sources were assigned high confidence levels; indicators with minor data gaps but clear core information were assigned medium confidence levels; and indicators with only basic information and generally unreliable sources were assigned low confidence levels. Simultaneously, considering the importance of each threat indicator in the overall threat assessment, a fixed weight was assigned to each indicator, with core dimensions such as impact scope and degree of damage having higher weights than other auxiliary dimensions. The quantitative result of each threat indicator was multiplied by its corresponding confidence level and weight, and all weighted results were then aggregated to form a fusion threat index that comprehensively reflects the overall threat level of the candidate related event sequence.

[0072] Collect the fusion threat index of all candidate related event sequences, classify and organize them according to the threat level corresponding to the score, and group sequences of the same threat level together. Conduct in-depth analysis of the correlation logic, behavioral triggering conditions, state transition patterns, and impact consequences of events in each group of sequences, extracting common behavioral characteristics and evolutionary patterns for each group; these common characteristics and patterns are the anomalous patterns. Provide a detailed description of each anomalous pattern, clarifying the core event components, chronological order, key triggering factors, potential risks and vulnerabilities, and the possible scope of harm. Systematically integrate all anomalous patterns, corresponding fusion threat indices, sequence details, risk analysis, and protection recommendations, arranging them according to a unified structure to form a comprehensive, logically clear, and directly applicable target network environment assessment report for cybersecurity decision-making.

[0073] The beneficial effects include the ability to perform standardized element analysis on multi-source heterogeneous logs of the target network environment, accurately obtain standardized events, effectively capture potential threat patterns through time-series dependency mining, and rapidly form logically rigorous candidate related event sequences through proactive traversal matching based on these patterns. Based on the candidate related event sequences, a targeted verification probe strategy is generated through reverse deduction. Applying this strategy to the target network environment and conducting incremental data collection yields accurate verification feedback data. Combining the feedback data with multi-dimensional threat quantification and confidence-weighted fusion of the candidate related event sequences accurately assesses the threat level and summarizes abnormal patterns, generating reliable analysis reports. This comprehensively improves the systematicness, accuracy, and efficiency of network anomaly behavior log correlation analysis, providing strong scientific support for network security protection decisions and effectively ensuring the safe and stable operation of the target network environment.

[0074] like Figure 2 The diagram shown is a functional block diagram of a log correlation analysis system for abnormal network operation behavior provided in an embodiment of the present invention.

[0075] The log correlation analysis system 10 for abnormal network operation behavior described in this invention can be installed in an electronic device. Depending on the functions implemented, the log correlation analysis system 10 may include a log normalization parsing module 11, a time-series dependency mining module 12, an active traversal matching module 13, a reverse inference verification module 14, an incremental verification and collection module 15, and a threat assessment and judgment module 16. The modules described in this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.

[0076] In this embodiment, the functions of each module / unit are as follows: The log normalization parsing module 11 is used to perform normalization element parsing on the multi-source heterogeneous logs of the target network environment to obtain the standardized events of the multi-source heterogeneous log stream. The time-series dependency mining module 12 is used to perform time-series dependency mining on the standardized events to obtain the potential threat patterns of the standardized events. The active traversal matching module 13 is used to actively traverse and match the standardized events based on the potential threat pattern to obtain a candidate associated event sequence of the standardized events. The reverse deduction verification module 14 is used to reverse deduce the subsequent evolution stages of the target network environment based on the candidate associated event sequence, and obtain the verification probe strategy for the subsequent evolution stages. The incremental verification acquisition module 15 is used to apply the verification probe strategy to the target network environment and perform incremental data acquisition on the target network environment to obtain verification feedback data of the target network environment. The threat assessment and judgment module 16 is used to assess the threat level of the candidate associated event sequence based on the verification feedback data, and obtain a judgment report of the target network environment.

[0077] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0078] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0079] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0080] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0081] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0082] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A log correlation analysis method for abnormal network operation behavior, characterized in that, The method includes: S01. Normalize the elements of the multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous logs. S02. Perform time-series dependency mining on the standardized events to obtain the potential threat patterns of the standardized events; S03. Based on the potential threat pattern, actively traverse and match the standardized events to obtain a candidate associated event sequence of the standardized events; S04. Based on the candidate associated event sequence, reverse the evolution of the target network environment to obtain the verification probe strategy for the subsequent evolution stage. S05. Apply the verification probe strategy to the target network environment and perform incremental data collection on the target network environment to obtain verification feedback data of the target network environment. S06. Based on the verification feedback data, assess the threat level of the candidate associated event sequence to obtain an analysis report of the target network environment.

2. The log correlation analysis method for abnormal network operation behavior as described in claim 1, characterized in that, The normalized element analysis of the multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous logs includes: A general format adaptation is performed on the multi-source heterogeneous logs of the target network environment to obtain formatted entries for the target network environment; The formatted entries are summarized using a terminology system to obtain the semantic events of the formatted entries; The semantic events are aligned with their spatiotemporal source identifiers to obtain the spatiotemporal reference events of the semantic events; Based on a preset unified event paradigm, the load structure of the spatiotemporal reference events is reorganized to obtain standardized events of the multi-source heterogeneous logs.

3. The log correlation analysis method for abnormal network operation behavior as described in claim 1, characterized in that, The step of performing time-series dependency mining on the standardized events to obtain the potential threat patterns of the standardized events includes: Invariant dependency topology discovery is performed on the normalized events to obtain the temporal dependency graph of the normalized events; The temporal dependency graph is subjected to multi-dimensional quantitative evaluation to obtain the high-value threat paths of the temporal dependency graph. The confidence level of the high-value threat path is calibrated, and the path after calibration is logically reconstructed to obtain the behavioral constraint rules of the high-value threat path. The behavioral constraint rules are formally encapsulated to obtain the potential threat patterns of the standardized events.

4. The log correlation analysis method for abnormal network operation behavior as described in claim 3, characterized in that, The step of performing multi-dimensional quantitative evaluation of the temporal dependency graph to obtain high-value threat paths in the temporal dependency graph includes: Anomaly propagation analysis is performed on the temporal dependency graph to obtain the threat paths of the temporal dependency graph; The hazard of the threat path is measured to obtain the destructive intensity of the threat path; Based on the damage intensity, the threat path is attenuated to obtain the attenuation coefficient of the threat path; Based on the damage intensity and the attenuation coefficient, a comprehensive threat score for the threat path is calculated, wherein the formula for calculating the comprehensive threat score is: ; In the formula, For the comprehensive threat score, The number of events in the threat path. For the threat path, the first The destructive intensity of the event, It is a natural exponential function. For the threat path, the first The decay coefficient of an event. As a preset environmental observability adjustment factor, It is the natural logarithm function. The standard deviation of the destructive intensity of all events in the threat path is given. This represents the average destructive intensity of all events along the threat path. Based on the comprehensive threat score, the threat paths are adaptively thresholded to obtain the high-value threat paths in the time-series dependency graph.

5. The log correlation analysis method for abnormal network operation behavior as described in claim 1, characterized in that, The step of actively traversing and matching the standardized events based on the potential threat patterns to obtain a candidate associated event sequence for the standardized events includes: Predictive operational encoding is performed on the potential threat pattern to obtain the detection command for the potential threat pattern; Based on the exploration command, the standardized events are retrieved in parallel to obtain the matching events of the standardized events; The matching events are further refined through feedback analysis to obtain a concise association between them. Based on the refined association, the standardized events are arranged according to temporal logic to obtain a sequence of candidate associated events for the standardized events.

6. The log correlation analysis method for abnormal network operation behavior as described in claim 1, characterized in that, The step of reverse-engineering the subsequent evolution stages of the target network environment based on the candidate associated event sequence to obtain the verification probe strategy for the subsequent evolution stages includes: Dynamic behavior slicing is performed on the candidate associated event sequence to obtain the behavior stage segment of the candidate associated event sequence; Logical completeness analysis is performed on the behavioral stage segment to obtain the logically unclosed interval of the behavioral stage segment; Based on the logically unclosed interval, the state transition path is deduced for the subsequent evolution stage of the target network environment to obtain the subsequent action sequence of the subsequent evolution stage; The subsequent action sequence is visualized and integrated to obtain the verification probe strategy for the subsequent evolution stage.

7. The log correlation analysis method for abnormal network operation behavior as described in claim 6, characterized in that, Based on the logically unclosed interval, the state transition path is deduced for the subsequent evolution stages of the target network environment to obtain the subsequent action sequence for the subsequent evolution stages, including: The policy profile is parsed for the logically unclosed intervals to obtain the intent description and observable tactical fingerprint of the logically unclosed intervals; Based on the observable tactical fingerprint, the dynamic protection effectiveness of the target network environment is evaluated to obtain the real-time defense resilience of the target network environment. Based on the intent description and the real-time defense resilience, attack path planning is performed on the logically unclosed interval to obtain the candidate action chain of the logically unclosed interval. Calculate the comprehensive opportunity index of the candidate action chain, wherein the formula for calculating the comprehensive opportunity index is: ; In the formula, The comprehensive opportunistic index is referred to here. At the starting time, The length of the time window. The preset time-varying decision preference coefficients, It is the natural logarithm function. For the candidate action chain at time... The expected progress contribution For the preset smallest positive number, As a preset time-varying factor of risk aversion, For the candidate action chain at time... Instantaneous risk exposure The cutoff time of the candidate action chain The cumulative operational feature entropy; Based on the comprehensive opportunistic index, the candidate action chain is globally optimized, and the steps of the optimized action chain are decoupled to obtain the subsequent action sequence of the subsequent evolution stage.

8. The log correlation analysis method for abnormal network operation behavior as described in claim 1, characterized in that, The step of applying the verification probe strategy to the target network environment and incrementally collecting data from the target network environment to obtain verification feedback data of the target network environment includes: The verification probe strategy is encapsulated into an executable form to obtain a deployable probe instance of the verification probe strategy; Based on the deployable probe instance, induced behavior is triggered in the target network environment to obtain the behavioral trajectory of the target network environment. Based on the behavioral trajectory, a controlled perturbation is injected into the interaction state of the target network environment to obtain the perturbation-post-state information of the target network environment. Based on the post-disturbance state information and the behavioral trajectory, targeted evidence collection is performed on the target network environment to obtain verification feedback data of the target network environment.

9. The log correlation analysis method for abnormal network operation behavior as described in claim 1, characterized in that, The step of assessing the threat level of the candidate associated event sequences based on the verification feedback data to obtain an analysis report of the target network environment includes: The verification feedback data is effectively discriminated and characterized to obtain the effective features of the verification feedback data; Based on the aforementioned effective features, multidimensional threat quantification is performed on the candidate associated event sequence to obtain the threat index of the candidate associated event sequence; The threat indicators are weighted and fused according to confidence level to obtain the fused threat index. Based on the fusion threat index, abnormal patterns are summarized in the candidate associated event sequences to obtain an assessment report of the target network environment.

10. A log correlation analysis system for abnormal network operation behavior, characterized in that, The system is used to implement the log correlation analysis method for abnormal network operation behavior as described in claim 1, the system comprising: The log normalization parsing module is used to perform normalization element parsing on multi-source heterogeneous logs in the target network environment to obtain the standardized events of the multi-source heterogeneous log stream. The temporal dependency mining module is used to perform temporal dependency mining on the standardized events to obtain the potential threat patterns of the standardized events. An active traversal matching module is used to actively traverse and match the standardized events based on the potential threat pattern to obtain a candidate associated event sequence of the standardized events. The reverse deduction verification module is used to reverse deduce the subsequent evolution stages of the target network environment based on the candidate associated event sequence, and obtain the verification probe strategy for the subsequent evolution stages. An incremental verification acquisition module is used to apply the verification probe strategy to the target network environment and perform incremental data acquisition on the target network environment to obtain verification feedback data of the target network environment. The threat assessment and analysis module is used to assess the threat level of the candidate related event sequence based on the verification feedback data, and obtain an analysis report of the target network environment.

Citation Information

Cited By

  • Transmission path planning method and device for controlled network environment data sharing and exchange

    CN121984912A

  • Method and apparatus for transmission path planning for controlled network environment data sharing exchange

    CN121984912B