A dynamic attack chain prediction system based on a knowledge graph and a neural network
Patent Information
- Application Number
- CN202611085267.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-21
- Publication Date
- 2026-09-29
AI Technical Summary
现有的攻击模拟工具(如Atomic Red Team)多依赖静态剧本,无法根据实时网络状态动态生成攻击路径
检测精度高且速度快:通过引入PPT-GNN架构,利用时空双流特征提取,提升检测精度。同时,基于滑窗的轻量化设计使得模型能够满足实时检测需求,解决了传统GNN检测延迟大的问题。
Smart Images

Figure CN122845252A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the interdisciplinary fields of cyberspace security, artificial intelligence, and deep learning, and in particular to a dynamic attack chain prediction system based on knowledge graphs and neural networks. Background Technology
[0002] As cyberattacks become increasingly automated, intelligent, and covert, Advanced Persistent Threats (APTs) have become a major risk to critical information infrastructure. Traditional network defense systems face three main challenges: Threat intelligence (CTI) is difficult to implement: Currently, threat intelligence is mostly in the form of unstructured reports written in natural language (such as PDFs and blogs). Although it contains rich TTPs (tactical, technical, and procedural) information, it relies on manual reading and rule extraction, which is inefficient and slow to update. Existing grammatical analysis-based tools (such as ThreatRaptor) struggle to handle complex domain-specific terminology (such as file paths and IP address obfuscation), resulting in a large amount of high-value intelligence failing to be transformed into machine-understandable defense rules.
[0003] Traffic detection models have poor practicality: In recent years, although intrusion detection systems based on graph neural networks (GNNs) have performed well in laboratory environments, they have serious shortcomings in real-world deployments. First, these models typically need to run on huge static graphs containing hours or even days of traffic, which cannot meet the requirements of real-time detection. Second, they require a large amount of labeled data specific to the network to be trained from scratch, making it difficult to quickly adapt to new network environments through few-shot learning.
[0004] Lack of dynamic simulation capabilities: Existing defense systems are mostly single-point defenses, meaning "detection equals blocking." However, APT attacks are often multi-stage attack chains. The lack of ability to predict the attacker's "next move" leaves defenders in a constantly passive and defensive position. Existing attack simulation tools (such as Atomic Red Team) mostly rely on static scripts and cannot dynamically generate attack paths based on real-time network conditions.
[0005] Therefore, there is an urgent need for a proactive defense solution that can deeply integrate external threat knowledge with internal traffic detection and can extrapolate future attack paths based on the current situation. Summary of the Invention
[0006] The purpose of this invention is to provide a dynamic attack chain prediction system based on knowledge graphs and neural networks, which can significantly improve the perception accuracy and proactive defense response speed of advanced persistent threats (APTs) in complex network environments.
[0007] To achieve the above objectives, this invention provides a dynamic attack chain prediction system based on knowledge graphs and neural networks, comprising: The intelligent intelligence perception and graph construction module is used to extract entities and reason about relationships from the collected threat intelligence to build a multi-level cybersecurity knowledge graph. The multi-level cybersecurity knowledge graph includes a physical domain graph, a logical threat graph, and a risk mapping graph. The pre-trained spatiotemporal graph network detection module is used to construct a spatiotemporal flow graph based on a sliding time window and extract traffic features using a hierarchical spatiotemporal aggregation mechanism. On unlabeled large-scale general network traffic data, context-independent pre-training is performed through a self-supervised link prediction task. Then, the synthetic attack traffic data generated by the dynamic attack chain inference module is executed in a simulation environment for self-supervised or supervised fine-tuning, and the detection results and confidence of abnormal nodes are output. The semantic enhancement feature fusion module is used to extract static semantic embedding vectors of nodes in the knowledge graph, and align and splice the static semantic embedding vectors with the dynamic spatiotemporal traffic features extracted from network traffic by the pre-trained spatiotemporal graph network detection module through a hierarchical spatiotemporal aggregation mechanism to construct enhanced node features with semantic cognition. The dynamic attack chain deduction module uses the abnormal state output by the pre-trained spatiotemporal graph detection module as the initial state. It combines the logical relationship graph in the knowledge graph, uses the planning domain definition language planner and causal reasoning algorithm to enhance the node features and provide the planner with an initial abnormal state with semantic understanding. This also affects the cost calculation of the attack path deduction and finally predicts the attacker's next action path and final goal, generating an attack prediction chain that includes the current attack stage, the next action, and the final goal. The graph incremental evolution feedback module connects the pre-trained spatiotemporal graph network detection module with the intelligent intelligence perception and graph construction module. When an abnormal subgraph structure with high confidence but unable to be matched in the current knowledge graph is detected, the original network logs and statistical features corresponding to the abnormal subgraph are extracted, converted into natural language descriptions, and reverse semantic generation is performed using a large language model. Combined with the enhanced node features constructed by the semantic enhancement feature fusion module, the module supports the identification of unknown threats, triggers the incremental update of the knowledge graph based on the large language model to construct new threat entity nodes and update them in the logical threat graph, thus realizing a knowledge loop for unknown threats. The simulation and data synthesis module connects the dynamic attack chain deduction module and the pre-trained spatiotemporal graph network detection module; it configures the simulation environment, automatically executes the attack prediction chain, synchronously collects network traffic during the execution process and automatically labels the attack type, generates a small sample fine-tuning dataset, and feeds it back to the pre-trained spatiotemporal graph network detection module for updates.
[0008] Preferred, multi-level cybersecurity knowledge graphs include: Physical domain graphs map network topology and physical connections; Tactics, techniques, and processes of logical threat graph mapping attack knowledge base framework; By entity alignment, the logical attack paths of the physical domain graph and the logical threat graph are mapped to the comprehensive risk relationships, forming a risk mapping graph.
[0009] Preferably, entity extraction and relational reasoning are performed, specifically as follows: By utilizing a large language model based on the Transformer architecture and designing prompt word templates, cluster analysis and causal discrimination are performed on predicates in unstructured text. When the model determines that predicate A implicitly leads to predicate B, a pseudo-action is automatically generated in the domain file of the planning domain definition language, with the precondition being predicate A and the effect being predicate B.
[0010] The preferred method for constructing the spatiotemporal flow graph is as follows: A line graph representation is used, initializing network flows as flow nodes and source and destination IPs as IP nodes. A heterogeneous graph is constructed using a knowledge-driven adaptive sliding time window mechanism. This knowledge-driven adaptive sliding time window mechanism includes: The intelligent intelligence perception module analyzes the latest threat intelligence in real time and analyzes the time granularity attributes of current high-risk attack techniques. When external intelligence indicates that the current network environment is facing low-frequency covert attack threats, the system actively issues control commands to automatically increase the time window parameter of the pre-trained spatiotemporal graph detection module to aggregate long-cycle sparse traffic features. When a high-frequency burst attack is warned, the time window parameter is decreased to capture instantaneous traffic mutations. Inter-window timing edges connect the same IP or flow in different time windows, and intra-window timing edges connect different flows under the same source IP or destination IP within the same time window. Inter-window timing edges and intra-window timing edges are timing connection edges.
[0011] The preferred hierarchical spatiotemporal aggregation mechanism includes the following specific calculation steps: Time aggregation: For nodes in the graph and time edge type Calculate the intermediate hidden states : ; in, and The weight matrix is a learnable matrix. For the first aggregation function, For nodes In edge type The following is a collection of neighbors. For the feature vector or hidden state of neighbor node u, Let v be a neighboring node. Let V be the set of neighboring nodes of node v under edge type e; Spatial aggregation: Based on the results of temporal aggregation, for spatial edge types Hidden states in computation space : ; Let e' be the weight matrix of the nodes themselves under the spatial edge type e'. The hidden features of node v after time aggregation. Let be the weight matrix of neighboring nodes under spatial edge type e'. It is the second aggregation function in the spatial dimension. The hidden features of neighbor node u after time aggregation are represented. Let $v$ be the set of neighbors of node $v$ under spatial edge type $e$. It is the feature set of all neighboring nodes of node v under spatial edge type e' after time aggregation; Finally, the node state is updated using a non-linear activation function: , It is a non-linear activation function. This is the final aggregation operation for all spatial edge type features.
[0012] Preferably, the loss function is pre-trained in context-independent manner through a self-supervised link prediction task. Defined as binary cross-entropy loss: ; In the formula, As the source node in the spatiotemporal flow graph, The target node (i.e., the positive sample) has a real connection with u. This is the set of real positive sample edges in the network. Let be the transpose of the hidden state feature vector of source node u. Let be the hidden state feature vector of the target node v. The hidden state feature vector of randomly sampled negative sample nodes (i.e., nodes that have no real connection with u); Self-supervised or supervised fine-tuning loss function : ; Where K is the size of the small sample dataset. The regularization coefficient is . For the k-th few-sample flow graph data, For the m-th input spatiotemporal flow graph (subgraph) data sample, These are the model parameters for the underlying pre-trained spatiotemporal graph network. These are the learnable parameters of the top-level classifier. The square of the L2 norm, For the model to input graph samples The predicted output probability distribution.
[0013] Preferably, the dynamic attack chain deduction module adopts a dynamic cost function mechanism: In planning problems using a domain definition language, the execution cost of attack actions is defined. Detection confidence of attack techniques corresponding to attack actions in the detection module of pre-trained spatiotemporal graph network They are inversely proportional, and the calculation formula is as follows: ; in, As the benchmark cost, For smoothing coefficients, a This refers to the specific attack actions within the planned domain.
[0014] Preferably, it also includes a dynamic feedback update mechanism: when a new unknown attack pattern is detected, a new attack description is generated using LLM and updated to the knowledge graph to achieve incremental learning of the graph.
[0015] Therefore, the present invention employs the aforementioned dynamic attack chain prediction system based on knowledge graphs and neural networks, and the technical effects are as follows: High detection accuracy and high speed: By introducing the PPT-GNN architecture and utilizing spatiotemporal dual-stream feature extraction, detection accuracy is improved. Meanwhile, the lightweight sliding window design enables the model to meet real-time detection requirements, solving the problem of high latency in traditional GNN detection.
[0016] Strong generalization ability and low deployment cost: Through self-supervised pre-training and "context-free" fine-tuning strategy, this system can achieve high data training effect with only a small amount of local labeled data, which greatly reduces the deployment threshold and labeling cost in edge scenarios such as the Internet of Things for power.
[0017] Proactive predictive capabilities: Unlike traditional passive alerts, this system combines a complete knowledge graph built using LLM (Limited Learning Model) with PDDL (Programming Process Dependency Level) planning algorithms to automatically predict the attacker's subsequent actions. This provides security personnel with invaluable insights for proactive defense decisions. Attached Figure Description
[0018] Figure 1 This is a diagram showing the overall architecture of the system of the present invention.
[0019] Figure 2This is a schematic diagram illustrating the model architecture and aggregation principle of a pre-trained spatiotemporal graph neural network (PPT-GNN).
[0020] Figure 3 A schematic diagram for constructing a multi-level network security knowledge graph.
[0021] Figure 4 This is a schematic diagram of the PDDL attack chain generation logic based on dynamic cost function.
[0022] Figure 5 This is a flowchart illustrating the closed-loop process of incremental evolution of the map and online fine-tuning of the model in response to unknown threats according to the present invention. Detailed Implementation
[0023] The technical solution of the present invention will be further described below with reference to the accompanying drawings and embodiments.
[0024] Unless otherwise defined, the technical or scientific terms used in this invention shall have the ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains.
[0025] Example 1 like Figure 1 As shown, a dynamic attack chain prediction system based on knowledge graphs and neural networks includes: Intelligent intelligence perception and graph construction module: used to collect network logs, vulnerability databases and open source threat intelligence (CTI) reports, use large language model (LLM) to perform entity extraction and relation reasoning, and construct a multi-level network security knowledge graph (CSKG); the graph includes a physical domain graph that maps network infrastructure, a logical threat graph that maps threat tactics and technologies, and a risk mapping graph that maps comprehensive risk relationships; In the intelligent intelligence perception and graph construction module, a fine-tuned LLM model is used to process unstructured threat intelligence reports (CTI), automatically extracting triplet relationships of "attacker-exploitation-vulnerability" and "vulnerability-existence-asset." A physical domain graph is constructed to map network topology physical connections, and a logical threat graph is constructed to map the tactics, techniques, and processes (TTPs) of the MITRE ATT&CK framework. Entity alignment technology is used to link the physical domain graph and the logical threat graph to form a risk mapping graph. Using the risk mapping graph (comprehensive risk graph) as a connection layer, the physical connections of the physical domain graph (network assets) are mapped to the logical attack paths of the logical threat graph (threat intelligence), forming a multi-modal knowledge base. To ensure the rigor of the graph construction, the following mathematical model is used to formally define and optimize the multi-level knowledge graph: Formal definition of multi-level cybersecurity knowledge graph: Define a multi-level cybersecurity knowledge graph as Where V represents the set of entity nodes and E represents the set of relation edges. For a collection of entity types, It is a set of relation types.
[0026] Physical domain layer infrastructure subgraph representation as ,in: For the set of entity nodes in the physical domain infrastructure graph, For the specific entity asset nodes in this set, To obtain the mapping function of type v corresponding to node, Internet Protocol address type, For network port type, Host device type, For the type of network service running on the host, the edge set This indicates the physical connection and service binding relationship.
[0027] The logical threat layer threat intelligence subgraph is represented as follows ,in Includes attack tactics, techniques, and vulnerability (CVE) nodes, edge set Includes logical attack paths (Implies, Requires).
[0028] The risk mapping subgraph is represented as ,in Includes cross-level mapping relationships, for example This indicates that a certain physical host has a certain logical vulnerability. To represent the logical layer entity node of a Common Vulnerability Disclosure (CVE), To represent the relationship edges that represent the "existence / ownership" cross-layer mapping relationship, This represents the asset nodes of the physical host.
[0029] The intelligent intelligence perception and graph construction module uses LLM for causal reasoning: it uses a large language model based on the Transformer architecture to perform cluster analysis and causal discrimination on predicates in unstructured text by designing specific prompt templates; when the model determines that predicate A implicitly leads to predicate B, it automatically generates a pseudo-action in the PDDL domain file, with the precondition being A and the effect being B, to improve the logical integrity of the attack chain.
[0030] This example details how to construct a CSKG using LLM.
[0031] Model fine-tuning: The robustly optimized pre-trained language model (RoBERTa) Chinese version was fine-tuned for the cybersecurity entity recognition task. Prompt design employs a "role-playing" strategy, for example: "You are a professional security engineer. Please analyze the following report and map it to the TTPs of the MITRE ATT&CK matrix...".
[0032] Causal Reasoning: Based on the extracted attack action descriptions, LLM analysis is used to analyze the causal relationships between predicates (e.g., whether "obtaining credentials" is a necessary condition for "lateral movement"). Prompt statements such as "Does variable A cause variable B? Please provide options A, B, C, D..." are used to refine the logical edges in the logical threat layer graph.
[0033] Graph generation: Extracted entities and relationships are stored in a high-performance graph storage engine, forming a visualized knowledge base using a graphical topology. When using the fine-tuned LLM for non-entity extraction (NER), considering that "attack entities" are extremely sparse compared to "background text" in threat intelligence text, this embodiment introduces a focal loss function to replace the traditional cross-entropy loss function in order to solve the class imbalance problem.
[0034] Let the model input be a CTI text sequence. The output labels are Define the loss function. as follows: in, It is the model's response to the real labels. The predicted probability, The balance factor (value 0.25). This is the focusing parameter (value 2.0). Through this loss function, the model training process reduces the weight of easily classified samples, focusing instead on sparse, difficult-to-identify threat entities.
[0035] like Figure 2 As shown, the pre-trained spatio-temporal graph network detection module (PPT-GNN) is used to construct a spatio-temporal flow graph based on a sliding time window. It extracts traffic features using a hierarchical spatio-temporal aggregation mechanism. It performs context-free (out-of-context) pre-training on unlabeled large-scale general network traffic data through a self-supervised link prediction task. Then, it uses synthetic attack traffic data generated by the dynamic attack chain inference module in a simulation environment for self-supervised or supervised fine-tuning, and outputs the detection results and confidence scores of abnormal nodes. The spatiotemporal flow graph construction method in the pre-trained spatiotemporal graph detection module (PPT-GNN) is as follows: A line graph representation is used, initializing network flows as flow nodes and source IPs and destination IPs as IP nodes; a heterogeneous graph is constructed through a knowledge-driven adaptive sliding time window mechanism. This mechanism includes: an intelligent intelligence perception module that analyzes the latest CTI intelligence in real time and analyzes the time granularity attribute of current high-risk attack techniques; when external intelligence indicates that the current network environment faces low-frequency covert attack threats, the system proactively issues control commands to automatically increase the PPT-GNN time window parameter (Twindow) to aggregate long-cycle traffic characteristics; when a 'high-frequency burst attack' is warned, the Twindow is decreased to capture instantaneous traffic mutations; the temporal connection edges include: inter-window temporal edges connecting the same IP or flow in different time windows, and intra-window temporal edges connecting different flows under the same source IP or destination IP within the same time window.
[0036] The pre-trained spatiotemporal graph detection module (PPT-GNN) adopts a hierarchical aggregation architecture, and the specific computation steps include: (1) Step (Time Aggregation): For the nodes in the graph and time edge type Calculate the intermediate hidden states : ; in, and The weight matrix is a learnable matrix. For the first aggregation function, For nodes In edge type The following is a collection of neighbors. For the feature vector or hidden state of neighbor node u, Let v be a neighboring node. Let v be the set of neighboring nodes of edge type e. Let v be the set of features of all neighboring nodes of node v under edge type e; (2) Steps (spatial aggregation): Based on the results of temporal aggregation, for spatial edge types Hidden states in computation space : ; Finally, the node state is updated using a non-linear activation function: , The hidden features of node v after time aggregation. Let be the weight matrix of neighboring nodes under spatial edge type e'. It is the second aggregation function in the spatial dimension. The hidden features of neighbor node u after time aggregation are represented. Let be the set of neighbors of node v under spatial edge type e'.
[0037] This embodiment details the implementation of the pre-trained spatiotemporal graph.
[0038] Graph structure initialization: The network flow data is converted into a line graph. The time window size is set to 5 seconds, and the window memory is 5 windows. Flow node features are directly taken from NetFlow v9 standard fields (such as Duration, Bytes, Packets), without using unavailable payload information to ensure usability.
[0039] Intelligence-driven adaptive window: The system establishes a linkage mechanism between threat intelligence and time windows. The intelligent intelligence perception module continuously monitors external CTI sources. For example, when the system parses the latest threat intelligence and determines that "an APT group is using slow scanning (T1046) to attack related industries," the system preemptively sends a control signal to the PPT-GNN to dynamically adjust the sliding window from the default 5 seconds to 60 seconds, putting the model into "long-cycle monitoring mode." This intelligence-based predictive mechanism effectively solves the problem of traditional GNNs missing detections due to excessively small windows when facing APT attacks with extremely long time spans.
[0040] like Figure 3 As shown, hierarchical aggregation calculation: (1) Time-series aggregation: The model first aggregates the historical states of the same node in different time windows to capture periodic patterns in traffic (such as the continuous high traffic of a distributed denial-of-service attack). Formula: ; In the formula, This represents the intermediate hidden state of a node after time aggregation. For the feature aggregation function in the time dimension, The state characteristics of a node in the current time window t. The state characteristics of the node in the previous time window t-1; (2) Spatial Aggregation: Subsequently, the topological relationships between source IPs and destination IPs within the same time window are aggregated to capture the lateral spread characteristics of the attack. Formula: ; The final node features are obtained after both temporal and spatial aggregation. It is a feature aggregation function in the spatial dimension. It is the set of topological neighbor node features within the same time window.
[0041] To more clearly illustrate the internal mechanism of PPT-GNN, the following provides the specific mathematical expressions for heterogeneous line graph construction and model training: (1) Construction mechanism of heterogeneous line graph Let the original network flow be ,in For source and destination IPs, "feat" represents the flow characteristics. In the online graph, each flow... Mapped to a node .
[0042] Spatial Edge Definition: If two flow nodes... and Establish spatial connection edges by sharing the same source or destination IP. .
[0043] Temporal Edge Definition: For a continuous stream sequence generated by the same pair of IP communications, a temporal connection edge is established across a time window. , This represents the state of a flow node within time window t. This represents the state of the same flow node in adjacent time windows t+1.
[0044] (2) Attention-based spatiotemporal aggregation formula In the "temporal aggregation" step, this embodiment specifically employs a multi-head attention mechanism to calculate the temporal context weights of nodes: This embodiment specifically employs a multi-head attention mechanism to calculate the temporal context weights of nodes: ; In the formula, Let v be the set of historical states of node v over time. These are the temporal context weight coefficients calculated in the attention mechanism. Let be the hidden features of a node within the historical time window t-τ, where t is the current reference time window. This is the time offset (i.e., the time delay span of the historical window).
[0045] Among them, attention coefficient The calculation is as follows: ; in This represents vector concatenation, where W is a learnable parameter. For the leaky modified linear unit nonlinear activation function, Let be the hidden state feature vector of node v in the current time window t. This is a joint representation of the features of the central node and the features of historical nodes. A learnable attention weight vector transpose, For node k in the time neighbor set within the historical time window The hidden state feature vector.
[0046] (3) Self-supervised pre-training loss function The pre-training phase employs a link prediction task, aiming to maximize the discriminative power between real-world spatiotemporal edges and randomly sampled negative edges. Loss function... Defined as binary cross-entropy loss: In the formula, As the source node in the spatiotemporal flow graph, To and There is a target node with a real connection. This is the set of real positive sample edges in the network. For the source node The transpose of the hidden state feature vectors. For the target node The hidden state feature vector, negative sample nodes that are randomly sampled The hidden state feature vector; By minimizing this loss, the model can learn the normal spatiotemporal topology distribution of network traffic without manual annotation.
[0047] (4) Few-sample fine-tuning loss function During the fine-tuning phase, the parameters of the underlying aggregation network are frozen, and only the top-level classifier (MLP) is updated. A regularization term is added to the loss function to prevent overfitting. ; Where K is the size of the small sample dataset. The regularization coefficient is . For the k-th few-sample flow graph data, For the m-th input spatiotemporal flow graph (subgraph) data sample, These are the model parameters for the underlying pre-trained spatiotemporal graph network. These are the learnable parameters of the top-level classifier. The square of the L2 norm, For the model to input graph samples The predicted output probability distribution.
[0048] Pre-training and fine-tuning: Pre-training was performed on an IoT security dataset based on network stream format, with the task of predicting randomly masked edges (link prediction). Fine-tuning was then performed on a comprehensive network intrusion dataset based on network stream format, using only 10% of the labeled data.
[0049] Semantic Enhancement Feature Fusion Module: This module extracts the static semantic embedding vectors of nodes in the knowledge graph and aligns and concatenates them with the dynamic spatiotemporal flow features extracted by PPT-GNN to construct enhanced node features with semantic cognition.
[0050] Dynamic attack chain deduction module: Based on the abnormal state output by the pre-trained spatiotemporal graph network detection module as the initial state, combined with the attack tactical relationship in the knowledge graph, the PDDL (Planning Domain Definition Language) planner and causal reasoning algorithm are used to predict the attacker's next action path and final goal, and generate an attack prediction chain containing "current attack stage - next action - final goal". The dynamic attack chain deduction module employs a dynamic cost function mechanism: In the PDDL planning problem, the execution cost of an attack action is defined. The detection confidence of the corresponding attack technique in the PPT-GNN module They are inversely proportional, and the calculation formula is as follows: ; in, As the benchmark cost, The smoothing coefficient is used to determine the probability of a certain attack technique occurring. The higher the probability that the detection model determines that a certain attack technique has occurred, the lower the cost for the planner to select that action when searching for a path, thus giving priority to generating attack paths that conform to the current real-time monitoring status.
[0051] This example illustrates how to generate attack predictions.
[0052] Problem definition: Suppose that PPT-GNN detects abnormal traffic on the internal network host 192.168.1.10 with a confidence level of 0.9.
[0053] like Figure 4 As shown, the PDDL file is generated: Domain file: Defines the action exploit_smb, which has the prerequisite of can_access_port_445 and the effect of has_admin_privileges.
[0054] Problem file: Initial state is set to compromised (192.168.1.10).
[0055] To achieve dynamic programming based on detection confidence, such as Figure 5 As shown, this embodiment first models the attack inference problem as a standard PDDL quintuple and defines the dynamic cost calculation logic: Define the planning problem ,in: A set of states, consisting of a series of predicates, such as... .
[0056] : A set of actions, each action Prerequisites and effects .
[0057] Cost function, mapping Each specific "attack action" (from the set) Each of these is assigned a specific value greater than 0 (from the set). This serves as the "cost" of performing the action.
[0058] It is a collection of objects, namely all operable assets, services, and entities in the current network environment. This refers to the initial state, which is the initial security posture mapped from the anomaly detection model of the GNN. The goal state is the final lateral movement or destructive objective that the attacker intends to achieve in the simulation.
[0059] To prevent the cost from becoming infinitely high due to extremely low detection confidence (close to 0), thus compromising the numerical stability of the planning solver, this embodiment uses a smoothed inverse proportional function to calculate the action cost. : ; in, PPT-GNN attack techniques The detection confidence level, Base value (default is 10.0). To prevent the minimum value of division by zero (take 1e-5). The penalty coefficient is... This represents the k-th candidate attack action in the attack deduction path. To find the minimum value Confidence of attack techniques detection The formula ensures that actions corresponding to high-confidence attacks have extremely low costs, thus guiding the planner to prioritize that path.
[0060] Cost Injection: Because the GNN detects a high risk, the cost of the action lateral_movement_from_10 is set to an extremely low value. The cost of other paths for which no anomalies were detected remains at the default value (e.g., 10.0).
[0061] Solution: By calling the classical programming solver, the system quickly outputs the attack path.
[0062] Closed-loop evolution and model update: The system not only outputs the predicted path to security managers but also simultaneously sends the PDDL planning results to the built-in sandbox environment. The sandbox-scheduled attack script automatically replays the attack behaviors (such as SMB Lateral Movement) along this path and records the generated traffic (PCAP / NetFlow). Since the attack behaviors are autonomously planned by the system, it can automatically and accurately label this traffic with attack tags. This synthetic data is immediately used to perform an online few-shot fine-tuning of the PPT-GNN model. The fine-tuned model weights are updated to the production environment, ensuring that the system can accurately detect the type of potential attack that was just predicted, achieving a minute-level response "from intelligence deduction to defense implementation".
[0063] The graph incremental evolution feedback module connects the pre-trained spatiotemporal graph detection module with the intelligent intelligence perception and graph construction module. When an abnormal subgraph structure with high confidence but cannot be matched in the current knowledge graph is detected, the original network logs and statistical features corresponding to the abnormal subgraph are extracted, the original network logs and statistical features are converted into natural language descriptions, and reverse semantic generation is performed using a large language model (LLM) to construct new threat entity nodes and update them in the logical threat layer graph, thereby achieving a knowledge loop for unknown threats (0-day). like Figure 5 As shown, this invention is not merely a one-way detection system, but also possesses the ability to self-evolve against unknown threats (0-day). The specific process includes the following steps: Anomaly detection and semantic reverse engineering: When the PPT-GNN detection module discovers a high-confidence anomalous traffic subgraph in the live network, but this subgraph cannot be matched with the existing logical threat layer knowledge graph, the system determines it as a potential new type of attack. The system extracts the statistical features and raw logs of this anomalous traffic and inputs them into the Large Language Model (LLM).
[0064] Incremental Graph Update: LLM leverages its powerful generalization capabilities to perform reverse semantic descriptions of unknown traffic (e.g., "Detected encrypted tunneling behavior based on non-standard ports") and formalizes it into new threat entity nodes, dynamically inserting them into the logical threat layer graph to achieve real-time expansion of the knowledge base.
[0065] Simulation verification and data synthesis: The dynamic attack chain deduction module generates new attack paths based on the updated graph and sends them to an isolated digital twin / sandbox environment. The sandbox automatically executes the attack script, "reproducing" the attack in a secure and controlled environment.
[0066] Online model fine-tuning: During the reproduction process, the system synchronously collects the generated traffic data and automatically adds precise attack labels. This batch of synthetic data is immediately fed back to the PPT-GNN module for few-sample fine-tuning of the model.
[0067] Closed loop complete: The finely tuned model parameters are updated to the detection engine, enabling the system to identify this type of new attack within a minute-level time window, achieving a defense closed loop from "unknown" to "known".
[0068] Simulation and Data Synthesis Module: This module connects the dynamic attack chain deduction module and the pre-trained spatiotemporal graph detection module. It configures an isolated digital twin or sandbox environment, automatically executes the attack prediction chain generated by the deduction module, synchronously collects network traffic during the execution process and automatically labels the attack type, generates a small-sample fine-tuning dataset, and feeds it back to the pre-trained spatiotemporal graph network detection module for model updates.
[0069] It also includes a dynamic feedback update mechanism: when a new unknown attack pattern (0-day) is detected, a new attack description is generated using LLM and updated to the knowledge graph, realizing incremental learning of the graph.
[0070] Therefore, the present invention employs the above-mentioned dynamic attack chain prediction system based on knowledge graphs and neural networks, which can significantly improve the perception accuracy and proactive defense response speed of advanced persistent threats (APTs) in complex network environments.
[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A dynamic attack chain prediction system based on knowledge graphs and neural networks, characterized in that, include: The intelligent intelligence perception and graph construction module is used to extract entities and reason about relationships from the collected threat intelligence and build a multi-level cybersecurity knowledge graph. A multi-level cybersecurity knowledge graph includes a physical domain graph, a logical threat graph, and a risk mapping graph. The pre-trained spatiotemporal graph network detection module is used to construct a spatiotemporal flow graph based on a sliding time window and extracts flow features using a hierarchical spatiotemporal aggregation mechanism. On unlabeled large-scale general network traffic data, context-independent pre-training is performed through a self-supervised link prediction task. Then, synthetic attack traffic data generated by the dynamic attack chain inference module is executed in a simulation environment for self-supervised or supervised fine-tuning, and the detection results and confidence of abnormal nodes are output. The semantic enhancement feature fusion module is used to extract static semantic embedding vectors of nodes in the knowledge graph, and align and splice the static semantic embedding vectors with the dynamic spatiotemporal traffic features extracted from network traffic by the pre-trained spatiotemporal graph network detection module through a hierarchical spatiotemporal aggregation mechanism to construct enhanced node features with semantic cognition. The dynamic attack chain deduction module uses the abnormal state output by the pre-trained spatiotemporal graph detection module as the initial state. It combines the logical relationship graph in the knowledge graph, uses the planning domain definition language planner and causal reasoning algorithm to enhance the node features and provide the planner with an initial abnormal state with semantic understanding. This also affects the cost calculation of the attack path deduction and finally predicts the attacker's next action path and final goal, generating an attack prediction chain that includes the current attack stage, the next action, and the final goal. The graph incremental evolution feedback module connects the pre-trained spatiotemporal graph network detection module with the intelligent intelligence perception and graph construction module. When an abnormal subgraph structure with high confidence but unable to be matched in the current knowledge graph is detected, the original network logs and statistical features corresponding to the abnormal subgraph are extracted, converted into natural language descriptions, and reverse semantic generation is performed using a large language model. Combined with the enhanced node features constructed by the semantic enhancement feature fusion module, the module supports the identification of unknown threats, triggers the incremental update of the knowledge graph based on the large language model to construct new threat entity nodes and update them in the logical threat graph, thus realizing a knowledge loop for unknown threats. The simulation and data synthesis module connects the dynamic attack chain deduction module and the pre-trained spatiotemporal graph network detection module; it configures the simulation environment, automatically executes the attack prediction chain, synchronously collects network traffic during the execution process and automatically labels the attack type, generates a small sample fine-tuning dataset, and feeds it back to the pre-trained spatiotemporal graph network detection module for updates.
2. The dynamic attack chain prediction system based on knowledge graphs and neural networks according to claim 1, characterized in that, A multi-level cybersecurity knowledge graph includes: Physical domain graphs map network topology and physical connections; Tactics, techniques, and processes of logical threat graph mapping attack knowledge base framework; By entity alignment, the logical attack paths of the physical domain graph and the logical threat graph are mapped to the comprehensive risk relationships, forming a risk mapping graph.
3. The dynamic attack chain prediction system based on knowledge graphs and neural networks according to claim 1, characterized in that, Entity extraction and relational reasoning are performed, specifically as follows: By utilizing a large language model based on the Transformer architecture and designing prompt word templates, cluster analysis and causal discrimination are performed on predicates in unstructured text. When the model determines that predicate A implicitly leads to predicate B, a pseudo-action is automatically generated in the domain file of the planning domain definition language, with the precondition being predicate A and the effect being predicate B.
4. The dynamic attack chain prediction system based on knowledge graphs and neural networks according to claim 1, characterized in that, The method for constructing a spatiotemporal flow graph is as follows: Using a line graph representation, network flows are initialized as flow nodes, and source IPs and destination IPs are initialized as IP nodes; Heterogeneous graphs are constructed using a knowledge-driven adaptive sliding time window mechanism; Knowledge The driver's adaptive sliding time window mechanism includes: The intelligent intelligence perception module analyzes the latest threat intelligence in real time and analyzes the time granularity attributes of current high-risk attack techniques. When external intelligence indicates that the current network environment is facing low-frequency covert attack threats, the system actively issues control commands to automatically increase the time window parameter of the pre-trained spatiotemporal graph detection module to aggregate long-cycle sparse traffic features. When a high-frequency burst attack is warned, the time window parameter is decreased to capture instantaneous traffic mutations. Inter-window timing edges connect the same IP or flow in different time windows, and intra-window timing edges connect different flows under the same source IP or destination IP within the same time window. Inter-window timing edges and intra-window timing edges are timing connection edges.
5. The dynamic attack chain prediction system based on knowledge graphs and neural networks according to claim 1, characterized in that, The hierarchical spatiotemporal aggregation mechanism includes the following specific computational steps: Time aggregation: For nodes in the graph and time edge type Calculate the intermediate hidden states : ; in, and The weight matrix is a learnable matrix. For the first aggregation function, For nodes In edge type The following is a collection of neighbors. For node u, the feature vector or hidden state. Let v be a neighboring node. Let V be the set of neighboring nodes of node v under edge type e; Spatial aggregation: Based on the results of temporal aggregation, for spatial edge types Hidden states in computation space : ; Let e' be the weight matrix of the nodes themselves under the spatial edge type e'. The hidden features of node v after time aggregation. Let be the weight matrix of neighboring nodes under spatial edge type e'. It is the second aggregation function in the spatial dimension. The hidden features of node u after time aggregation are shown. Let $v$ be the set of neighbors of node $v$ under spatial edge type $e$. It is the feature set of all neighboring nodes of node v under spatial edge type e' after time aggregation; Finally, the node state is updated using a non-linear activation function: , It is a non-linear activation function. This is the final aggregation operation for all spatial edge type features.
6. The dynamic attack chain prediction system based on knowledge graphs and neural networks according to claim 1, characterized in that, Loss function pre-trained using a self-supervised link prediction task with context-independent training Defined as binary cross-entropy loss: ; In the formula, As the source node in the spatiotemporal flow graph, To and There is a target node with a real connection. This is the set of real positive sample edges in the network. For the source node The transpose of the hidden state feature vectors. For the target node The hidden state feature vector, For randomly sampled negative sample nodes The hidden state feature vector; Self-supervised or supervised fine-tuning loss function : ; Where K is the size of the small sample dataset, The regularization coefficient is . For the k-th few-sample flow graph data, For the m-th input spatiotemporal flow graph (subgraph) data sample, These are the model parameters for the underlying pre-trained spatiotemporal graph network. These are the learnable parameters of the top-level classifier. The square of the L2 norm. For the model to input graph samples The predicted output probability distribution.
7. The dynamic attack chain prediction system based on knowledge graphs and neural networks according to claim 1, characterized in that, The dynamic attack chain deduction module employs a dynamic cost function mechanism: In planning problems using a domain definition language, the execution cost of attack actions is defined. Detection confidence of attack techniques corresponding to attack actions in the detection module of pre-trained spatiotemporal graph network They are inversely proportional, and the calculation formula is as follows: ; in, As the benchmark cost, For smoothing coefficients, a This refers to the specific attack actions within the planned domain.
8. The dynamic attack chain prediction system based on knowledge graphs and neural networks according to claim 1, characterized in that, It also includes a dynamic feedback update mechanism: when a new unknown attack pattern is detected, a new attack description is generated using LLM and updated to the knowledge graph, realizing incremental learning of the graph.