Information security threat determination method and information security threat determination device
The information security threat detection method and device address the challenge of distinguishing between non-security and security-related events in 5G networks by employing a causal tree inspection and decision chain process, achieving precise threat identification and reducing false positives.
Patent Information
- Application Number
- JP2023198018
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-26
- Filing Date
- 2023-11-22
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing technologies face challenges in effectively identifying information security threats within 5G networks, as many abnormal events are not actually caused by security threats, leading to a need for improved methods to distinguish between non-security and security-related events.
An information security threat detection method and device that utilize a causal tree inspection process, generate multiple cause trackings, deploy virtual terminals and service endpoints to communicate through the core network, and execute a decision chain process to determine whether an abnormal event is a non-information security threat or an information security threat.
This approach enables precise identification of information security threats by narrowing down the inspection range through multiple analysis and verification rounds, thereby accurately confirming security threats and reducing false positives.
Smart Images

Figure 2025073942000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a threat determination method and a threat determination device, and more particularly to an information security threat determination method and an information security threat determination device. [Background technology]
[0002] The open architecture of fifth-generation mobile communications technology (5G) networks means that any network element that complies with the standards and interface specifications can be networked, making it possible to detect abnormal conditions in the entire 5G network from various aspects through external systems.
[0003] In addition, the information security central control platform of the 5G network usually receives a large number of abnormal event warnings, but few of them are actually caused by information security threats. Therefore, there is an urgent need in this field for a method and device that can effectively identify security threats. Summary of the Invention [Problem to be solved by the invention]
[0004] The technical problem that the present invention aims to solve is to provide an information security threat determination method and an information security threat determination device that compensate for the shortcomings of existing technology and are capable of determining an abnormal event as a non-information security threat event or an information security threat event. [Means for solving the problem]
[0005] In order to solve the above technical problems, one of the technical solutions adopted by the present invention is to provide an information security threat determination method applicable to a network system including a terminal, a core network and a service endpoint. The information security threat determination method performed by the information security threat determination device includes: receiving information of an abnormal event occurring in the network system, performing a causal tree inspection process to generate multiple cause traces based on the abnormal event, verifying whether each trace cause may cause the abnormal event by deploying virtual terminals and virtual service endpoints to communicate through the core network, and generating an inspection result; performing a judgment chain process to determine the abnormal event as a non-information security threat event or an information security threat event based on the inspection result.
[0006] In order to solve the above technical problems, another technical solution adopted by the present invention is to provide an information security threat determination device applicable to a network system including a terminal, a core network, and a service endpoint. The information security threat determination device includes a storage and a processor, and the storage is configured to store information of an abnormal event occurring in the network system. The processor is electrically connected to the storage. The processor is configured to execute a causal tree inspection process and generate a plurality of cause traces based on the abnormal event, and the processor is configured to verify whether each trace cause may cause the abnormal event by deploying a virtual terminal and a virtual service endpoint to communicate through the core network, and generate an inspection result. The processor executes a judgment chain process and judges the abnormal event as a non-information security threat event or an information security threat event based on the inspection result.
[0007] In order to further understand the characteristics and technical contents of the present invention, please refer to the following detailed description and illustrations of the present invention. However, the illustrations provided are only for reference and explanation, and are not intended to limit the present invention. [Brief description of the drawings]
[0008] [Figure 1] 1 is a functional block diagram of an information security threat determination device according to an embodiment of the present invention. [Diagram 2] 2 is a flowchart of an information security threat determination method according to an embodiment of the present invention. [Diagram 3] 1 is a flowchart of a causal tree testing process in an embodiment of the present invention. [Figure 4] 1 is a schematic diagram showing how a processor of an information security threat determination device according to an embodiment of the present invention is configured to execute a causal tree checking process. [Diagram 5] 1 is a flowchart of an end-to-end exploration process in an embodiment of the present invention. [Figure 6] 2 is a schematic diagram showing that a processor of an information security threat determination device in an embodiment of the present invention is configured to execute an end-to-end exploration process. FIG. [Figure 7] 4 is a flowchart of a key data acquisition process in an embodiment of the present invention. [Figure 8] 1 is a flow chart of a decision chain process in an embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] The following describes the embodiments of the present invention with specific examples. Those skilled in the art can understand the advantages and effects of the present invention from the disclosure of this specification. The present invention can be implemented or applied in other different embodiments. Each detail in this specification can be modified and changed based on various aspects or applications without departing from the spirit of the present invention. In addition, the drawings of the present invention are for simple and schematic illustration only and do not show actual dimensions. The following embodiments further describe technical matters related to the present invention, but the disclosed contents do not limit the present invention.
[0010] Please refer to Figures 1 and 2. Figure 1 is a functional block diagram of an information security threat determination device in an embodiment of the present invention, and Figure 2 is a flowchart of an information security threat determination method in an embodiment of the present invention. As shown in Figure 1, an information security threat determination device 10 of this embodiment is applied to a network system 12 including a terminal 120, a core network 122, and a service endpoint 124 (i.e., the information security threat determination device 10 can be connected to the network system 12), and the information security threat determination device 10 includes a storage 100 and a processor 102.
[0011] The storage 100 is configured to store information of an abnormal event (i.e., content reflecting the abnormal event, not depicted in FIG. 1) occurring in the network system 12. The processor 102 is electrically connected to the storage 100 and can be realized by a combination of hardware (e.g., a central processing unit and memory), software and / or firmware. However, the specific embodiment of the storage 100 and the processor 102 is not limited by the present invention.
[0012] As shown in FIG. 2, the information security threat determination method of the present embodiment is executed by an information security threat determination device 10 and includes the following steps.
[0013] Step S111: Information about an abnormal event that has occurred in the network system is received.
[0014] Specifically, the information security threat determination device 10 is configured to receive information on an abnormal event occurring in the network system 12 and store the information on the abnormal event in the storage 100. In this embodiment, the network system 12 is a system of a 5G network, and the information on the abnormal event may be generated by an external system of the 5G network. The terminal 120, the core network 122, and the service endpoint 124 are user equipment (User Equipment, UE), a core network, and a data network (Data Network, DN) in the 5G network, respectively, and the core network 122 is connected between the terminal 120 and the service endpoint 124. In addition, the above-mentioned external system includes an operation and maintenance (OAM) system, an information security detection system, a network traffic monitoring system, etc. of the 5G network, but the present invention is not limited thereto.
[0015] In general, the core network of the 5G network may include an Access and Mobility Function (AMF), a Session Management Function (SMF), and a User Plane Function (UPF), and the OAM system may detect an abnormal operation event of a Network Function (NF) of the core network. In addition, the information security detection system may detect an event such as a login abnormality of a user equipment (UE), and the network segment traffic monitoring system may detect a traffic abnormality event of a network segment (e.g., an N2 interface, an N3 interface, or an N6 interface). In other words, the above-mentioned external system may effectively detect an abnormal state of the 5G network by approaching it from different aspects, and the information security threat determination device 10 may receive information of the abnormal event from the above-mentioned external system.
[0016] Based on the above, different systems (i.e., OAM system, information security detection system, and network segment traffic monitoring system, etc.) can detect abnormal events from different sources. In addition, different abnormal events simultaneously detected by different systems are likely to be caused by the same information security threat. Therefore, in another embodiment, when the information security threat determination device 10 receives information on multiple abnormal events simultaneously detected by the above-mentioned external systems, the information security threat determination device 10 may be configured to select one of the multiple abnormal events as the main target of source analysis.
[0017] Step S112: Perform a causal tree inspection process, generate multiple cause tracings based on the abnormal event, and verify whether each tracing cause can cause the abnormal event by deploying virtual terminals and virtual service endpoints to communicate through the core network, and generate an inspection result.
[0018] Further, the processor 102 is configured to execute a causal tree checking process, which generates multiple cause traces (not depicted in FIG. 1) based on the abnormal event, and verifies whether each trace cause may cause the abnormal event by deploying virtual terminals and virtual service endpoints (also not depicted in FIG. 1) to communicate through the core network 122. Also refer to FIG. 3. FIG. 3 is a flowchart of the causal tree checking process in an embodiment of the present invention. As shown in FIG. 3, the causal tree checking process may include the following steps.
[0019] Step S121: An analysis process is performed on the abnormal event, and multiple causal traces are generated based on the inspection rule set.
[0020] Step S122: A verification process is performed for each causal trace to verify whether the causal trace can cause the abnormal event.
[0021] Referring to Fig. 4, Fig. 4 is a schematic diagram in which a processor of an information security threat determination device in an embodiment of the present invention is configured to execute a causal tree inspection process. As shown in Fig. 4, in a time period T11 in which an analysis process is executed for an abnormal event 400, the processor 102 can generate multiple cause traces corresponding to the abnormal event 400 based on an inspection rule set (not shown in Fig. 4). For ease of explanation, in this embodiment, an example is shown in which the processor 102 generates five cause traces 501 to 505 corresponding to the abnormal event 400, but the present invention is not limited thereto.
[0022] Specifically, the inspection rule set includes multiple inspection rules, which may be preset or added through a decision chain process. These inspection rules define cause tracings corresponding to different abnormal events. For example, for an abnormal event of "the communication speed is slow after the user equipment (UE, i.e., terminal 120) logs into the 5G network", the cause tracings may include "the central processing unit of the network function (NF) is fully operational", "the memory of the NF is fully operational", "the storage of the NF is fully operational", "the data flow of the N3 interface is clogged", and "the registration setting of the UE is tampered with by a malicious third party", but the present invention is not limited thereto. Therefore, if the abnormal event 400 is the above-mentioned abnormal event, the processor 102 can generate the above-mentioned cause tracing.
[0023] Next, in a time period T12 for performing a verification process for each causal trace, the processor 102 can verify whether each causal trace may cause the abnormal event 400 by deploying a virtual terminal and a virtual service endpoint to communicate through the core network 122. For ease of understanding, the causal trace determined not to cause the abnormal event 400 is shown to be excluded by marking it with a cross in this embodiment. In addition, the verification process performed for each causal trace may include an end-to-end exploration process. Please refer to FIG. 5. FIG. 5 is a flowchart of the end-to-end exploration process in the embodiment of the present invention. As shown in FIG. 5, the end-to-end exploration process may include the following steps.
[0024] Step S131: Configure the probe management module to register a virtual terminal with a core network.
[0025] Step S132: Configure the probe management module to deploy virtual terminals and virtual service endpoints to communicate through the core network based on the abnormal event and cause tracking.
[0026] Step S133: Configure the virtual terminal to transmit uplink data.
[0027] Step S134: Configure the virtual service endpoint to analyze the uplink data and report the first probe data to the probe management module.
[0028] Step S135: Configure the virtual service endpoint to transmit the downlink data.
[0029] Step S136: Configure the virtual terminal to analyze the downlink data and report the second probe data to the probe management module.
[0030] Step S137: configure the probe management module to report the first probe data and the second probe data to the processor. The processor verifies whether the cause tracing may cause the abnormal event according to the first probe data and the second probe data.
[0031] Specifically, the probe management module can be realized by a combination of hardware and software and / or firmware. However, the present invention is not limited to a specific embodiment of the probe management module. Please also refer to FIG. 6. FIG. 6 illustrates an example in which the processor of the information security threat determination device in the embodiment of the present invention is configured to execute an end-to-end search process. For ease of explanation, the present embodiment illustrates an example in which the processor 102 executes an end-to-end search process for cause tracing 501. As shown in FIG. 6, the processor 102 is configured to allow the probe management module 104 to register the virtual terminal 220 in the core network 122, and further deploy the virtual terminal 220 and the virtual service endpoint 224 based on the abnormal event 400 and the cause tracing 501, and communicate through the core network 122.
[0032] In other words, the present invention uses a virtual terminal 220 to mimic the operation of a specific user equipment (UE), and the virtual service endpoint 224 is a virtual data network. Then, the probe management module 104 configures the virtual terminal 220 to transmit uplink data TD1. The uplink data TD1 transmitted by the virtual terminal 220 is transmitted to the virtual service endpoint 224 through the core network 122. The virtual service endpoint 224 may also be configured to analyze the received uplink data TD1 and report the first probe data PD1 to the probe management module 104.
[0033] Meanwhile, the probe management module 104 can configure the virtual service endpoint 224 to send downlink data TD2, and the downlink data TD2 sent by the virtual service endpoint 224 is transmitted to the virtual terminal 220 through the core network 122. In addition, the virtual terminal 220 can analyze the received downlink data TD2 and report the second probe data PD2 to the probe management module 104. The present invention is not limited to the specific contents of the uplink data TD1 sent by the virtual terminal 220 and the downlink data TD2 sent by the virtual service endpoint 224. In addition, the probe management module 104 is configured to report the first probe data PD1 and the second probe data PD2 to the processor 102, and the processor 102 can verify whether the cause tracing 501 may cause the abnormal event 400 based on the first probe data PD1 and the second probe data PD2.
[0034] In addition, the use of the end-to-end search process in this embodiment can also achieve the purpose of "checking whether the transmission data at the UE / DN end has been tampered with", "checking whether the system is under DoS attack", "checking whether the connection of the N2 / N3 / N6 interface is stable", "checking whether the operation record of the UE / base station (e.g., gNB) has been tampered with", etc., but the present invention is not limited thereto. When using the end-to-end search process to check whether the transmission data at the UE end has been tampered with, the uplink data TD1 sent by the virtual terminal 220 is information security sensitive data (e.g., medical images, financial data, industry qualifications, political images, etc.), and the virtual service endpoint 224 can compare the received uplink data TD1 with the information security sensitive data to generate the first search data PD1.
[0035] The details of "checking whether the transmission data at the DN end has been tampered with" using the end-to-end search process follow the above content, so they will not be described repeatedly here. In addition, the verification process for each cause tracing may also include a key data acquisition process. See FIG. 7. FIG. 7 is a flowchart of the key data acquisition process in an embodiment of the present invention. As shown in FIG. 7, the key data acquisition process may include the following steps:
[0036] Step S141: Obtain configuration data and real-time operation data of a core network.Step S142: Based on the configuration data and the real-time operation data, verify whether cause tracing may cause an abnormal event.
[0037] Specifically, the configuration data of the core network 122 is the configuration data of the network function (NF), and is used to verify whether the current cause tracing may cause the abnormal event 400. In addition, the real-time operation data of the core network 122 includes the health status of each part of the core network, the usage rate of operation resources, the transmission performance of the network, and various logs of the NF.
[0038] Taking the above content as an example, when using an end-to-end search process to "check whether the connection of the N2 / N3 / N6 interface is stable", if the processor 102 determines that the connection of the N2 / N3 / N6 interface is unstable, it can use the acquired configuration data and real-time operation data of the core network 122 to check whether the connection instability of the N2 / N3 / N6 interface is caused by malicious operation. Furthermore, the processor 102 can perform a certain operation to acquire the configuration data and real-time operation data of the core network 122, and verify whether the NF of the core network 122 is normal.
[0039] In addition, after going through the analysis process and the verification process, the processor 102 can eliminate some cause tracing, but in order to obtain better inspection results, the processor 102 can perform multiple rounds of analysis and verification processes. That is, the present embodiment uses the principle of causal tree analysis to explore the cause of the abnormal event 400. The advantage of using causal tree analysis in the present embodiment is that it can gradually narrow down the inspection scope and more accurately confirm information security threats. Therefore, as shown in FIG. 3, the causal tree inspection process can also include the following steps:
[0040] Step S123: Obtain a set of causal traces determined to cause the abnormal event, and derive at least one event trace based on the set of causal traces.
[0041] Step S124: Perform an analysis process on the at least one event trace to regenerate a plurality of causal traces based on the test rule set.
[0042] Step S125: Again perform the verification process for each causal trace to verify whether the causal trace can cause the abnormal event.
[0043] As shown in FIG. 4, in response to obtaining that the set of causal traces verified to cause the abnormal event includes the causal trace 502 and the causal trace 503, the processor 102 can derive the event trace 411 and the event trace 412 based on the causal trace 502 and the causal trace 503, but the present invention is not limited thereto. It is described that the inspection rule set also includes a rule for deriving the event trace based on the causal trace. Furthermore, in the time period T21 in which the analysis process for the event trace 411 and the event trace 412 is performed, the processor 102 can regenerate multiple causal traces corresponding to the event trace 411 and the event trace 412 based on the inspection rule set. That is, the above-mentioned inspection rule also defines causal traces corresponding to different event traces. For ease of explanation, the present embodiment shows an example in which the processor 102 regenerates two causal traces 511, 512 corresponding to the event trace 411 and one causal trace 513 corresponding to the event trace 412, but the present invention is not limited thereto.
[0044] As can be seen from the above, the analysis process performed in time period T11 is regarded as the first round of analysis process, and the analysis process performed in time period T21 is regarded as the second round of analysis process. Similarly, the verification process performed in time period T12 is regarded as the first round of verification process, and the verification process performed in time period T22 is regarded as the second round of verification process. In the second round of verification process, the processor 102 verifies whether each of the cause traces 511 to 513 may cause the abnormal event 400. For ease of explanation, an example of performing two rounds of analysis process and verification process is shown in this embodiment. Therefore, after performing the second round of verification process, the processor 102 can generate the inspection result 600.
[0045] In other words, since the present embodiment is an example of performing two rounds of analysis and verification processes, after step S125 in Fig. 3, the causal tree inspection process may include step S126: generating an inspection result. The content of the inspection result 600 may indicate "there is no information security threat", "there is a single information security threat", or "multiple information security threats exist simultaneously", but the present invention is not limited thereto. In the present embodiment, the cause tracing 512 determined to cause the abnormal event 400 is related only to the information security threat of "malicious network blocking attack", so the processor 102 may generate the inspection result 600 with the content "there is a single information security threat".
[0046] In another embodiment, if too many causal traces are determined to cause the abnormal event and the information security threat cannot be accurately identified, the processor 102 can perform the next round of analysis and verification processes. That is, before proceeding to step S126 of the causal tree inspection process, the processor 102 can repeatedly perform steps S123 to S125 to narrow the inspection scope until the information security threat can be more accurately identified. The relevant details are similar to those described above, so they will not be described in detail here.
[0047] Meanwhile, as shown in FIG. 2, the information security threat determination method of this embodiment proceeds to step S113: executing a determination chain process, and can determine the abnormal event as a non-information security threat event or an information security threat event based on the inspection result.
[0048] In other words, the processor 102 is configured to execute a decision chain process, and can determine the abnormal event 400 as a non-information security threat event or an information security threat event based on the inspection result 600. Please refer to FIG. 8. FIG. 8 is a flowchart of the decision chain process of an embodiment of the present invention. As shown in FIG. 8, the decision chain process can include the following steps:
[0049] Step S151: Perform a marking process to determine and mark the abnormal event as a non-information security threat event or an information security threat event based on the inspection result.
[0050] Step S152: Using the information security threat event as a label and the overall operation data exhibited by the network system during the abnormal event as training data, a training process is performed to train a machine learning model.
[0051] Step S153: A feedback process is performed to update the inspection rule set during the analysis process based on the machine learning model.
[0052] Specifically, when it is confirmed that one of the causal tracings that cause the abnormal event 400 is related to an information security threat, the processor 102 can determine and mark the abnormal event 400 as an information security threat event based on the inspection result 600. Based on the above, since the causal tracing 512 is related to the information security threat of “malicious network shutdown attack”, the processor 102 can not only generate the inspection result 600 indicating that “a single information security threat exists”, but also determine and mark the abnormal event 400 as an information security threat event based on the inspection result 600.
[0053] In contrast, if the cause trace 512 that is the cause of the abnormal event 400 is verified to be not related to information security threats, the processor 102 can not only generate the inspection result 600 indicating that there is no information security threat, but also determine and mark the abnormal event 400 as a non-information security threat event based on the inspection result 600. Also, based on the above, in order to enable the processor 102 to generate the cause trace 512 faster, another key point of the decision chain process is to update the inspection rule set during the analysis process. That is, the next time the processor 102 receives information of the same abnormal event, the processor 102 can generate the cause trace 512 in the first round of the analysis process based on the updated inspection rule set, thereby saving the time and cost of the processor 102 to perform the causal tree inspection process.
[0054] To update the inspection rule set during the analysis process, the processor 102 can use the information security threat event as a tag and train a machine learning model using the overall operation data of the network system 12 when the abnormal event 400 occurs as training data. The processor 102 can then update the inspection rule set during the analysis process based on the machine learning model. For example, a new inspection rule can be added to the current inspection rule set or an existing inspection rule can be deleted. Taking the above as an example, the cause tracking 501 has been proven to have a low relevance to the abnormal event 400, and the processor 102 can delete the inspection rule that associates the cause tracking 501 with the abnormal event 400 based on the machine learning model, so as not to increase the possibility of false positives. It should be noted that updating the inspection rule set also includes adjusting the rules for the cause tracking event.
[0055] Furthermore, the processor 102 can collect overall operation data of the network system 12 when the abnormal event 400 occurs, and use the overall operation data of the network system 12 as features for model training. Also, the machine learning model can identify what kind of information security threat has occurred based on the overall operation data of the network system 12 when the abnormal event 400 occurs. For example, the information security threat determination device 10 can include a database (not shown), which is used to store overall operation data of the network system 12 when different information security threats occur.
[0056] Therefore, the machine learning model can compare the overall operation data of the network system 12 when the abnormal event 400 occurs with the overall operation data stored in the database, and generate threat level scores corresponding to different information security threats through the comparison. A higher threat level score means that the corresponding information security threat is more likely to occur. After each identification, the processor 102 can compare the identification result with the actual confirmation result by humans. If the identification result is wrong (i.e., the identification result is different from the actual result), the processor 102 can add the sample to the training data and retrain the machine learning model.
[0057] In other words, the processor 102 utilizes an incremental learning method to allow the machine learning model to dynamically receive new data and learn using the new data. Therefore, the machine learning model of the present embodiment can continuously self-learn and correct errors. In this case, the present embodiment does not need to retrain the entire model. Furthermore, after the machine learning model has been trained for multiple rounds, it not only gradually corrects the cause tracing generated by the analysis process, but also gradually enhances the accuracy of self-identifying information security threats. Even if the usage situation of the network system 12 changes, the machine learning model can self-learn, correct errors, and maintain high accuracy.
[0058] In summary, one beneficial effect of the present invention is that the information security threat determination method and information security threat determination device provided by the present invention can determine an abnormal event as a non-information security threat event or an information security threat event through the technical means of "generating multiple cause tracings based on an abnormal event, deploying virtual terminals and virtual service endpoints to communicate through a core network, and checking whether each cause tracing causes an abnormal event." Furthermore, the information security threat determination method and information security threat determination device provided by the present invention can gradually narrow down the inspection scope through multiple rounds of analysis and verification processes, and more precisely identify information security threats.
[0059] Furthermore, the information security threat determination method and the information security threat determination device provided by the present invention can verify whether the cause tracing causes the abnormal event through an end-to-end search process, and can gradually correct the cause tracing generated by the analysis process through a decision chain process.
[0060] The above-described invention is merely a preferred embodiment of the present invention, and does not limit the scope of the claims of the present invention. Therefore, all equivalent technical modifications based on the contents of the specification and accompanying drawings of the present invention are intended to be included in the scope of the claims of the present invention. [Explanation of symbols]
[0061] 10. Information security threat assessment device 100 Storage 102 processors 104 Probe Management Module 220 Virtual Terminals 224 Virtual Service Endpoints 12 Network Systems 120 terminals 122 Core Network 124 Service Endpoints 400 Abnormal Event 501~505, 511~513 Cause tracing 411, 412 Event Tracking 600 Test Results T11, T12, T21, T22 Time Zone TD1 Uplink Data TD2 downlink data PD1, PD2 exploration data S111~S113, S121~S126, S131~S137, S141~S142, S151~S153 Steps
Claims
1. An information security threat determination method applied to a network system including a terminal, a core network, and a service endpoint, comprising: The information security threat determination method includes: receiving information about an abnormal event that has occurred in the network system; Executing a causal tree testing process, which generates multiple causal traces based on the abnormal event, and deploys virtual terminals and virtual service endpoints to communicate through the core network to verify whether the multiple causal traces cause the abnormal event, thereby generating a test result; performing a decision chain process to determine the anomalous event as a non-information security threat event or an information security threat event based on the inspection result; An information security threat determination device is configured to execute the 1. A method for determining an information security threat, comprising:
2. The causal tree testing process further comprises: performing an analysis process on the anomalous events to generate the plurality of causal traces based on a set of testing rules; performing a verification process for the plurality of causal traces to verify whether the causal traces cause the abnormal event; The information security threat determination method according to claim 1 , comprising:
3. The verification process performed for each of the causal traces includes an end-to-end search process, the end-to-end search process comprising: configuring a probe management module to register the virtual terminal with the core network; configuring the probe management module to deploy the virtual terminals and the virtual service endpoints to communicate through the core network based on the abnormal event and the cause tracking; configuring the virtual terminal to transmit uplink data; configuring the virtual service endpoint to analyze the uplink data and report first probe data to the probe management module; configuring the virtual service endpoint to transmit downlink data; configuring the virtual terminal to analyze the downlink data and report second probe data to the probe management module; Configuring the probe management module to report the first probe data and the second probe data to a processor, the processor verifying whether the cause tracing causes the abnormal event based on the first probe data and the second probe data; The information security threat determination method according to claim 2 , comprising:
4. The causal tree testing process further comprises: obtaining at least one set of causal traces verified to cause the abnormal event, and deriving at least one event trace based on the set of causal traces; executing the analysis process on the at least one event trace to regenerate the causal trace based on the set of testing rules; again performing the verification process for each of the causal traces to verify whether the causal traces may cause the abnormal event; The information security threat determination method according to claim 2 , comprising:
5. The verification process performed for each of the causal traces further includes a key data acquisition process, obtaining configuration data and real-time operational data of the core network; Verifying whether the causal tracing may cause the abnormal event based on the configuration data and the real-time operation data; The information security threat determination method according to claim 3 , comprising:
6. The decision chain process comprises: performing a marking process to determine and mark the abnormal event as the non-information security threat event or the information security threat event based on the inspection result; Running a training process, in which the information security threat event is a label, and the network system uses overall operation data at the time of the abnormal event as training data to train a machine learning model; performing a feedback process to update the inspection rule set during the analysis process based on the machine learning model; The information security threat determination method according to claim 2 , comprising:
7. The information security threat determination method of claim 6, wherein in response to one of the causal traces verified to cause the abnormal event being associated with an information security threat, the marking process determines and marks the abnormal event as the information security threat event based on the inspection result.
8. An information security threat determination device that is applied to a network system including a terminal, a core network, and a service endpoint and includes a storage device and a processor, The storage is configured to store information about an abnormal event that has occurred in the network system; The processor is electrically connected to the storage, and is configured to execute a causal tree testing process and a decision chain process; The causal tree inspection process generates a plurality of causal traces based on the abnormal event, and deploys virtual terminals and virtual service endpoints to communicate through the core network to verify whether the plurality of causal traces cause the abnormal event, thereby generating an inspection result; The information security threat determination device, characterized in that the determination chain process determines the abnormal event as a non-information security threat event or an information security threat event based on the inspection result.
9. The causal tree checking process performed by the processor further comprises: performing an analysis process on the anomalous events to generate the plurality of causal traces based on a set of testing rules; performing a verification process for the plurality of causal traces to verify whether the causal traces cause the abnormal event; The information security threat determination device according to claim 8 .
10. The verification process performed by the processor for each of the causal traces includes an end-to-end search process, the end-to-end search process comprising: configuring a probe management module to register the virtual terminal with the core network; configuring the probe management module to deploy the virtual terminals and the virtual service endpoints to communicate through the core network based on the abnormal event and the cause tracking; configuring the virtual terminal to transmit uplink data; configuring the virtual service endpoint to analyze the uplink data and report first probe data to the probe management module; configuring the virtual service endpoint to transmit downlink data; configuring the virtual terminal to analyze the downlink data and report second probe data to the probe management module; Configuring the probe management module to report the first probe data and the second probe data to a processor, the processor verifying whether the cause tracing causes the abnormal event based on the first probe data and the second probe data; The information security threat determination device according to claim 9 .
11. The causal tree checking process performed by the processor further comprises: obtaining at least one set of causal traces verified to cause the abnormal event, and deriving at least one event trace based on the set of causal traces; executing the analysis process on the at least one event trace to regenerate the causal trace based on the set of testing rules; again performing the verification process for each of the causal traces to verify whether the causal traces may cause the abnormal event; The information security threat determination device according to claim 9 .
12. The verification process performed by the processor for each of the cause traces further includes a key data acquisition process, obtaining configuration data and real-time operational data of the core network; Verifying whether the causal tracing may cause the abnormal event based on the configuration data and the real-time operation data; The information security threat determination device according to claim 10 .
13. The decision chain process executed by the processor comprises: executing a marking process to determine and mark the anomalous event as the non-information security threat event or the information security threat event based on the inspection result executed by the processor; Running a training process, in which the information security threat event is a label, and the network system uses overall operation data at the time of the abnormal event as training data to train a machine learning model; performing a feedback process to update the inspection rule set during the analysis process based on the machine learning model; The information security threat determination device according to claim 9 .
14. The information security threat determination device of claim 13, wherein in response to one of the causal traces verified to cause the abnormal event being associated with an information security threat, the processor determines and marks the abnormal event as the information security threat event based on the inspection result.
Citation Information
Patent Citations
Endpoint Security Using Behavioral Prediction Models
JP2023523079A
Treating data flows differently based on interest
JP2023524619A