Method and apparatus for generating cyber kill chain, and electronic device

By generating network kill chains, the correlation analysis of multi-source logs and security alarm logs is used, combined with pre-trained detection and generation models, the problems of low detection accuracy and inability to fully demonstrate the attack process in the prior art are solved, and high-accurate attack recognition and interpretable network kill chain generation are achieved.

WO2025108041A1PCT designated stage expired Publication Date: 2025-05-30CHINA TELECOM NETWORK SECURITY TECH CO LTD

Patent Information

Application Number
PCT/CN2024/129129
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-20
Filing Date
2024-10-31
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing cyber attack detection methods are not very accurate in detection, which is prone to false alarms and missed reports, and cannot fully display multiple links and detailed information in the attack process, affecting security personnel's comprehensive assessment and timely response to cyber security threats.

Method used

By generating multi-source logs and security alarm logs, aggregating security alarm logs, associating multi-source logs to obtain user behavior sequences, using pre-trained detection models to detect attack traffic, and when attack traffic is detected, the generative model is used to generate network kill chains.

Benefits of technology

It significantly improves the accuracy of attack identification, enhances the interpretability of attack detection, and helps security personnel to comprehensively evaluate and promptly respond to cybersecurity threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024129129_30052025_PF_FP_ABST
    Figure CN2024129129_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a method and apparatus for generating a cyber kill chain, and an electronic device. The method comprises: generating multi-source logs and security alarm logs on the basis of network traffic and terminal behaviors; performing aggregation processing on the security alarm logs to obtain aggregated security alarm logs, and associating the aggregated security alarm logs with the multi-source logs to obtain a user behavior sequence; inputting the user behavior sequence into a pre-trained detection model to detect, on the basis of the detection model, whether there is attack traffic in the user behavior sequence; and when there is attack traffic in the user behavior sequence, inputting the user behavior sequence into a pre-trained generation model to generate, on the basis of the generation model, a cyber kill chain corresponding to the attack traffic. By means of the method, the recognition efficiency and accuracy of detecting the attack traffic can be improved, and the cyber kill chain corresponding to the attack traffic can be accurately restored, so that the cybersecurity personnel can comprehensively assess and promptly deal with cybersecurity threats.
Need to check novelty before this filing date? Find Prior Art

Description

Method, device and electronic device for generating a network kill chain

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese patent application number 202311545268.9, filed with the State Intellectual Property Office of the People's Republic of China on November 20, 2023, entitled "A method, device and electronic device for generating a network kill chain", the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of network security technology, and in particular to a method, device, and electronic device for generating a network kill chain. Background Art

[0004] With the rapid development of network technology, cybersecurity threats have become increasingly complex and diverse. Cyber ​​attackers are employing increasingly covert, multi-layered, and multi-source attack methods, posing significant challenges to network security. Promptly identifying cyberattacks and accurately restoring the attack chain are crucial to ensuring network security.

[0005] Existing network attack detection methods rely solely on single logs to detect anomalies. Due to the limited information captured, detection accuracy is low and prone to false positives and missed negatives. When an attack is detected, the alerts generated by network security protection devices are limited to a single stage, failing to fully capture the multiple steps and detailed information involved in the attack. This makes it difficult for security personnel to obtain the full context and accurate information about the attack, hindering their ability to comprehensively assess and promptly respond to network security threats.

[0006] Summary of the Invention

[0007] The present application provides a method, apparatus, and electronic device for generating a network kill chain to obtain the complete context and accurate information of an attack, thereby helping network security personnel to comprehensively assess and promptly respond to network security threats.

[0008] In a first aspect, the present application provides a method for generating a network kill chain, the method comprising:

[0009] Generate multi-source logs and security alert logs based on network traffic and terminal behavior, where the multi-source logs are original logs from different device terminals;

[0010] Aggregating the security alarm log to obtain an aggregated security alarm log, and correlating the multi-source logs based on the aggregated security alarm log to obtain a user behavior sequence, wherein the user behavior sequence is a sequence of behavior records generated by the same user on the different devices arranged in chronological order;

[0011] Inputting the user behavior sequence into a pre-trained detection model, and detecting whether there is attack traffic in the user behavior sequence based on the detection model;

[0012] When attack traffic exists in the user behavior sequence, the user behavior sequence is input into a pre-trained generation model, and a network kill chain corresponding to the attack traffic is generated based on the generation model.

[0013] In one possible design, before generating multi-source logs and security alert logs based on network traffic and terminal behavior, it also includes: inputting any multi-source log data into a large model for pre-training to obtain a first large model; adding a classification layer to the first large model to obtain a second large model, and inputting the first sample log data set into the second large model for training to obtain the detection model, wherein the first sample log data set is a collection of each associated multi-source log data arranged and spliced ​​in time sequence and carrying labels, the associated multi-source log data is all log data associated with the same user, and the label is an attack traffic label or a normal traffic label; inputting the second sample log data set into the first large model for training to obtain the generation model that outputs a text description of the network kill chain, wherein the second sample log data set is a collection of each associated multi-source log data arranged and spliced ​​in time sequence and carrying the attack traffic label.

[0014] In one possible design, associating the multi-source logs based on the aggregated security alarm log to obtain a user behavior sequence includes: associating the aggregated security alarm log with the multi-source log to obtain all log data; obtaining all behavior records of the same user from all the log data; and arranging all the behavior records in chronological order to obtain the user behavior sequence.

[0015] In one possible design, the original logs of different device ends include network-side logs, end-side logs, and service logs.

[0016] In one possible design, the network kill chain includes the attacker's intrusion path, attack means, and attack target.

[0017] In a second aspect, the present application provides a device for generating a network kill chain, the device comprising:

[0018] A first generation module generates multi-source logs and security warning logs based on network traffic and terminal behavior, wherein the multi-source logs are original logs from different device terminals;

[0019] a log correlation module that aggregates the security alarm log to obtain an aggregated security alarm log, and correlates the multi-source logs based on the aggregated security alarm log to obtain a user behavior sequence, wherein the user behavior sequence is a sequence of behavior records generated by the same user on the different devices arranged in chronological order;

[0020] an attack detection module, which inputs the user behavior sequence into a pre-trained detection model and detects whether there is attack traffic in the user behavior sequence based on the detection model;

[0021] The second generation module, when attack traffic exists in the user behavior sequence, inputs the user behavior sequence into a pre-trained generation model, and generates a network kill chain corresponding to the attack traffic based on the generation model.

[0022] In one possible design, the device is further used to: input any multi-source log data into a large model for pre-training to obtain a first large model; add a classification layer to the first large model to obtain a second large model, and input the first sample log data set into the second large model for training to obtain the detection model, wherein the first sample log data set is a collection of each associated multi-source log data arranged and spliced ​​in time sequence and carrying labels, the associated multi-source log data is all log data associated with the same user, and the label is an attack traffic label or a normal traffic label; input the second sample log data set into the first large model for training to obtain the generation model that outputs a text description of the network kill chain, wherein the second sample log data set is a collection of each associated multi-source log data arranged and spliced ​​in time sequence and carrying the attack traffic label.

[0023] In one possible design, the log association module is specifically used to: associate the aggregated security alarm log with the multi-source log to obtain all log data; obtain all behavior records of the same user from all log data; and arrange all behavior records in chronological order to obtain the user behavior sequence.

[0024] In one possible design, the original logs of different device ends include network-side logs, end-side logs, and service logs.

[0025] In one possible design, the network kill chain includes the attacker's intrusion path, attack means, and attack target.

[0026] In a third aspect, the present application provides an electronic device, comprising:

[0027] Memory for storing computer programs;

[0028] The processor is configured to implement the above method steps when executing the computer program stored in the memory.

[0029] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the computer program implements the above-mentioned method steps for generating a network kill chain.

[0030] For each of the above-mentioned aspects from the second to the fourth aspects and the technical effects that may be achieved by each of the aspects, please refer to the above-mentioned description of the technical effects that can be achieved by the first aspect or various possible solutions in the first aspect, and no further details will be given here. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] FIG1 is a flow chart of a method for generating a network kill chain provided by the present application;

[0032] FIG2 is a flow chart of a training detection model and a generation model provided by the present application;

[0033] FIG3 is a structural diagram of a possible application framework provided by this application;

[0034] FIG4 is an example diagram of input and output of a detection model provided by this application;

[0035] FIG5 is an example diagram of an input and output of a generation model provided by this application;

[0036] FIG6 is a schematic diagram of a device for generating a network kill chain provided by the present application;

[0037] FIG7 is a schematic diagram of the structure of an electronic device provided by the present application. DETAILED DESCRIPTION

[0038] In order to make the purpose, technical solutions and advantages of this application more clear, the application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments.

[0039] In the description of this application, "multiple" is understood to mean "at least two." "And / or" describes the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. A and B are connected, which can mean: A and B are directly connected, and A and B are connected through C. In addition, in the description of this application, words such as "first" and "second" are used only for the purpose of distinguishing descriptions and should not be understood as indicating or implying relative importance or order.

[0040] To help those skilled in the art better understand the technical solutions provided by the embodiments of the present application, the following is a brief description of the professional terms involved:

[0041] A cyber kill chain refers to the series of steps an attacker follows during a cyberattack, from the initial attack point to the target, encompassing multiple stages and behaviors. Typically, a cyber kill chain consists of six key phases: network scanning, intrusion and penetration, persistence (privilege escalation), lateral movement, execution of targeted actions, and obfuscation and cleanup. Each phase may leave traces in various device logs, including security device logs, application service logs, and operating system logs.

[0042] Large Models: Large Language Models (LLMs), also known as large language models, are AI models designed to understand and generate human language. They are trained on large amounts of text data and can perform a wide range of tasks, including text summarization, translation, sentiment analysis, and more. LLMs are characterized by their large size, containing billions of parameters, which help them learn complex patterns in language data.

[0043] The following is a brief introduction to the design concept of the embodiments of this application.

[0044] In view of the increasingly complex multi-level and multi-source characteristics of network security threats and attacks, an embodiment of the present application provides a method for generating a network kill chain. In the first stage, through the correlation analysis of multi-source logs, the alarm information generated by the network security protection equipment can be analyzed more deeply. By performing a comprehensive analysis of the correlated multi-source logs through a pre-trained detection model, advanced attacks that have not been detected by the network security protection equipment can be identified, significantly improving the accuracy of attack identification. In the second stage, a network kill chain is generated by generating a model, and the scattered single-stage alarms are integrated into a multi-stage network kill chain, presenting a full picture of the attack and improving the interpretability of attack detection. This method can significantly improve the accuracy of attack identification, while enhancing the interpretability of attack detection, which helps to comprehensively assess network security threats and respond in a timely manner.

[0045] The method provided in the embodiments of the present application is described in detail below with reference to the accompanying drawings.

[0046] FIG1 is a flow chart of a method for generating a network kill chain according to an embodiment of the present application. The specific implementation process of the method is as follows:

[0047] Step 101: Generate multi-source logs and security alert logs based on network traffic and terminal behavior;

[0048] Step 102: Aggregate the security alarm log to obtain an aggregated security alarm log, and associate the aggregated security alarm log with multiple source logs to obtain a user behavior sequence;

[0049] Step 103: Input the user behavior sequence into the pre-trained detection model, and detect whether there is attack traffic in the user behavior sequence based on the detection model;

[0050] Step 104: When attack traffic exists in the user behavior sequence, the user behavior sequence is input into a pre-trained generation model, and a network kill chain corresponding to the attack traffic is generated based on the generation model.

[0051] In an embodiment of the present application, before performing attack detection and network kill chain restoration on network traffic and terminal behavior, it also includes training a detection model and a generation model. The detection model is used to perform attack detection on network traffic and terminal behavior entering the system environment, and the generation model is used to restore the network kill chain of attack traffic.

[0052] Specifically, see Figure 2, which is a flow chart of the training detection model and the generation model provided in the embodiment of the present application. The specific implementation process is as follows:

[0053] Step 201: Input any multi-source log data into a large model for pre-training to obtain a first large model;

[0054] In an embodiment of the present application, any multi-source log data is massive multi-source log data. Multi-source logs are original logs from different device ends. The original logs from different device ends may include: network side logs, terminal side logs, and service logs.

[0055] Network-side logs: mainly record network-side traffic, including full traffic records and various network-side alarm logs.

[0056] Device-side logs: Mainly record the operations and behaviors of terminal devices, applications, or clients, such as user interactions, device status, error logs, application events, etc.

[0057] Service log: mainly records information at the application layer, including specific business service logs and database operation logs.

[0058] Specifically, massive amounts of multi-source log data are fed into a large model for pre-training. This input is a basic large model using a decoder structure. After analyzing and learning this massive amount of multi-source log data, a primary model is generated. This primary model provides a more comprehensive and in-depth understanding of various logs in complex systems, providing stronger support for log analysis, attack detection, and network kill chain restoration.

[0059] Step 202: Add a classification layer to the first large model to obtain a second large model, and input the first sample log data set into the second large model for training to obtain a detection model;

[0060] In an embodiment of the present application, based on the first large model obtained by the above pre-training, fine-tuning training is performed for different application scenarios to obtain models with different functions.

[0061] Specifically, when the application scenario is attack detection, a classification layer is added to the first model to perform category detection on the training dataset. The classification layer can be, but is not limited to, a Softmax layer. The Softmax layer is a layer commonly used in neural networks for multi-class classification problems. Its main function is to convert the input into a probability distribution.

[0062] In this embodiment of the present application, a first sample log data set is used as a training data set. The first sample log data set is a collection of labeled, linked multi-source log data arranged and spliced ​​in time sequence. The linked multi-source log data is all log data associated with the same user, and the labels are either attack traffic labels or normal traffic labels. That is, all the labeled log data associated with different users is arranged and spliced ​​in time sequence, then input into the second largest model for classification training, outputting the categories of all log data associated with each user.

[0063] It is worth noting that the categories of all log data associated with each detected user are not limited to attack categories and non-attack categories, but can also include multiple different attack categories, such as DDos attacks, SQL injection attacks, cross-site scripting attacks, etc.

[0064] After the first sample log data set is input into the second largest model for training to obtain the detection model, the detection model is optimized using the cross entropy loss function.

[0065] Building a detection model based on the first large model after analyzing and learning massive multi-source logs can enable the detection model to perform in-depth analysis and processing of logs, thereby detecting advanced attacks, reducing missed attacks and false positives, and improving the accuracy of attack identification.

[0066] Step 203: Input the second sample log data set into the first large model for training to obtain a generation model that outputs a text description of the network kill chain.

[0067] Specifically, when the application scenario involves generating a network kill chain, the second sample log dataset is fed into the first large model for training, resulting in a generative model that outputs a textual description of the network kill chain. The second sample log dataset is a collection of linked multi-source log data, arranged and concatenated in chronological order, carrying attack traffic labels. Linked multi-source log data refers to all log data associated with the same user. Specifically, all log data associated with different users identified as attack traffic is arranged and concatenated in chronological order, then fed into the first large model for training, outputting a textual description of each attack traffic flow.

[0068] Building a generative model based on the first model after analyzing and learning massive multi-source logs allows the generative model to directly process complete, original log information without the need for dimensionality reduction or other preprocessing methods, ensuring that the generated network kill chain is more accurate and the information is more comprehensive.

[0069] After the detection model and the generative model are trained, they are organically combined to detect attacks based on network traffic and terminal behavior, as well as restore the network kill chain. See Figure 1 for the specific process:

[0070] Step 101: Generate multi-source logs and security alert logs based on network traffic and terminal behavior;

[0071] In the embodiment of the present application, the multi-source logs are original logs from different device ends, and the original logs from different device ends include network-side logs, terminal-side logs, and service logs.

[0072] See Figure 3, which shows the application framework structure for generating a network kill chain according to an embodiment of the present application. Specifically, the log collection module collects all network traffic and terminal behavior in the system environment, generating multi-source logs (network-side logs, terminal-side logs, and service logs) and security alert logs.

[0073] Step 102: Aggregate the security alarm log to obtain an aggregated security alarm log, and associate the aggregated security alarm log with multiple source logs to obtain a user behavior sequence;

[0074] Specifically, security alert logs are aggregated to generate an aggregated security alert log. The aggregated security alert log is then correlated with multi-source logs to obtain all log data. Within this log data, network-side, device-side, and service-side records generated by the same user behavior are correlated to obtain all behavior records for the same user. All behavior records for each user are then arranged in chronological order to obtain a complete user behavior sequence.

[0075] Step 103: Input the user behavior sequence into a pre-trained detection model, and detect whether there is attack traffic in the user behavior sequence based on the detection model;

[0076] After obtaining the user behavior sequence, the user behavior sequence is input into the pre-trained detection model for attack detection. Taking Figure 4 as an example, the input of the detection model can be the user behavior sequence arranged in time sequence, and the output can be the classification label (attack traffic / normal traffic).

[0077] If attack traffic is detected in the user behavior sequence, the user behavior sequence is input into the pre-trained generative model. At the same time, the detection model will also output an alert indicating that the user behavior sequence is attack traffic.

[0078] Step 104: When attack traffic exists in the user behavior sequence, the user behavior sequence is input into a pre-trained generative model, and a network kill chain corresponding to the attack traffic is generated based on the generative model.

[0079] Specifically, when attack traffic is detected in a user behavior sequence, the user behavior sequence is input into a pre-trained generative model. The generative model makes predictions based on the input user behavior sequence and outputs a text description, namely the network kill chain.

[0080] For example, as shown in Figure 5, the input of the generation model can be the user behavior sequence with attack traffic determined by the above detection model, and the output is a text description, which is the network kill chain, including the attacker's intrusion path, attack means and attack target, etc.

[0081] The network kill chain generated by the generative model describes the complete process and accurate information of the attack, which helps network security personnel to comprehensively assess network security threats and respond in a timely manner.

[0082] This application integrates multi-source log data from different network devices, applications, and systems to provide a comprehensive data view for network security analysis. This comprehensive data fusion method breaks through the traditional single data source limitation, making network security analysis more comprehensive and accurate. At the same time, after using a large model to conduct in-depth analysis and learning of massive multi-source log data, a detection model and a generation model are trained. This can ensure that the trained detection model can perform high-dimensional analysis of the input log information, improve the detection model's recognition efficiency and accuracy in detecting attack traffic, and ensure that the trained generation model can completely and accurately restore the network kill chain, thereby improving the accuracy of restoring the network kill chain.

[0083] Based on the same inventive concept, this application also provides a network kill chain device for obtaining the complete context and accurate information of an attack, thereby assisting network security personnel in comprehensively assessing and promptly responding to network security threats. Referring to FIG6 , the device includes:

[0084] The first generating module 601 generates multi-source logs and security warning logs based on network traffic and terminal behavior, wherein the multi-source logs are original logs from different device terminals;

[0085] The log correlation module 602 aggregates the security alarm log to obtain an aggregated security alarm log, and correlates the multi-source logs based on the aggregated security alarm log to obtain a user behavior sequence, wherein the user behavior sequence is a sequence of behavior records generated by the same user on different devices arranged in chronological order;

[0086] Attack detection module 603, inputs the user behavior sequence into a pre-trained detection model, and detects whether there is attack traffic in the user behavior sequence based on the detection model;

[0087] The second generation module 604 inputs the user behavior sequence into a pre-trained generation model when attack traffic exists in the user behavior sequence, and generates a network kill chain corresponding to the attack traffic based on the generation model.

[0088] In one possible design, it is characterized in that the device is also used to: input any multi-source log data into a large model for pre-training to obtain a first large model; add a classification layer to the first large model to obtain a second large model, and input the first sample log data set into the second large model for training to obtain the detection model, wherein the first sample log data set is a collection of each associated multi-source log data arranged and spliced ​​in time sequence and carrying labels, the associated multi-source log data is all log data associated with the same user, and the label is an attack traffic label or a normal traffic label; input the second sample log data set into the first large model for training to obtain the generation model that outputs a text description of the network kill chain, wherein the second sample log data set is a collection of each associated multi-source log data arranged and spliced ​​in time sequence and carrying the attack traffic label.

[0089] In one possible design, the log association module 602 is specifically used to: associate the aggregated security alarm log with the multi-source log to obtain all log data; obtain all behavior records of the same user from all log data; and arrange all behavior records in chronological order to obtain the user behavior sequence.

[0090] In one possible design, the original logs of different device ends include network-side logs, end-side logs, and service logs.

[0091] In one possible design, the network kill chain includes the attacker's intrusion path, attack means, and attack target.

[0092] Based on the above-mentioned device, by integrating multi-source log data from different network devices, applications, and systems, a comprehensive data view is provided for network security analysis. This comprehensive data fusion method breaks through the limitations of traditional single data sources, making network security analysis more comprehensive and accurate. Simultaneously, by using large models to deeply analyze and learn massive amounts of multi-source log data, detection models and generative models are trained. This ensures that the trained detection model can perform high-dimensional analysis of input log information, improving the detection model's recognition efficiency and accuracy in detecting attack traffic. It also ensures that the trained generative model can completely and accurately restore the network kill chain, improving the accuracy of restoring the network kill chain.

[0093] Based on the same inventive concept, an embodiment of the present application further provides an electronic device that can implement the functions of the aforementioned apparatus for generating a network kill chain. Referring to FIG. 7 , the electronic device includes:

[0094] At least one processor 701, and a memory 702 connected to at least one processor 701. The specific connection medium between the processor 701 and the memory 702 is not limited in the embodiments of the present application. FIG7 takes the connection between the processor 701 and the memory 702 via the bus 700 as an example. The bus 700 is represented by a bold line in FIG7. The connection between other components is only for schematic illustration and is not intended to be limiting. The bus 700 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one bold line is used in FIG7, but this does not mean that there is only one bus or one type of bus. Alternatively, the processor 701 can also be called a controller, and there is no limitation on the name.

[0095] In this embodiment of the present application, memory 702 stores instructions executable by at least one processor 701. By executing the instructions stored in memory 702, at least one processor 701 can perform the method for generating a network kill chain discussed above. Processor 701 can implement the functions of each module in the apparatus shown in Figure 6.

[0096] Among them, the processor 701 is the control center of the device, which can use various interfaces and lines to connect the various parts of the entire control device, and monitor the device as a whole by running or executing instructions stored in the memory 702 and calling data stored in the memory 702, the various functions of the device and processing data.

[0097] In one possible design, processor 701 may include one or more processing units. Processor 701 may integrate an application processor and a modem processor. The application processor primarily processes the operating system, user interface, and application programs, while the modem processor primarily processes wireless communications. It is understood that the modem processor may not be integrated into processor 701. In some embodiments, processor 701 and memory 702 may be implemented on the same chip. In some embodiments, they may also be implemented on separate chips.

[0098] Processor 701 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the various methods, steps, and logic diagrams disclosed in the embodiments of this application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method for generating a network kill chain disclosed in the embodiments of this application can be directly implemented and executed by a hardware processor, or by a combination of hardware and software modules in the processor.

[0099] The memory 702 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 702 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (Random Access Memory, RAM), a static random access memory (Static Random Access Memory, SRAM), a programmable read-only memory (Programmable Read Only Memory, PROM), a read-only memory (Read Only Memory, ROM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a magnetic memory, a disk, an optical disk, etc. The memory 702 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory 702 in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.

[0100] By programming processor 701, the code corresponding to the method for generating a network kill chain described in the aforementioned embodiment can be embedded within the chip, enabling the chip to execute the steps of the method for generating a network kill chain as shown in FIG1 during operation. Designing and programming processor 701 is well known to those skilled in the art and will not be further described here.

[0101] Based on the same inventive concept, an embodiment of the present application further provides a storage medium storing computer instructions. When the computer instructions are executed on a computer, the computer executes the method for generating a network kill chain discussed above.

[0102] In some possible implementations, various aspects of the method for generating a network kill chain provided in the present application may also be implemented in the form of a program product, which includes program code. When the program product is run on an apparatus, the program code is used to cause the control device to execute the steps of the method for generating a network kill chain according to various exemplary embodiments of the present application described above in this specification.

[0103] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0104] The present application is described with reference to the flow chart and / or block diagram of the method, device (system), and computer program product according to the embodiment of the present application. It should be understood that each flow process and / or box in the flow chart and / or block diagram and the combination of the flow process and / or box in the flow chart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processing machine or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for realizing the function specified in one flow chart flow or multiple flows and / or one box or multiple boxes of the block diagram.

[0105] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0106] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0107] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A method for generating a network kill chain, characterized in that: The method comprises: Generate multi-source logs and security warning logs based on network traffic and terminal behavior, where the multi-source logs are original logs from different device terminals; Aggregate the security alarm log to obtain an aggregated security alarm log, and associate the multi-source logs based on the aggregated security alarm log to obtain a user behavior sequence, wherein the user behavior sequence is a sequence in which the behavior records generated by the same user on the different device terminals are arranged in time sequence; Inputting the user behavior sequence into a pre-trained detection model, and detecting whether there is attack traffic in the user behavior sequence based on the detection model; When attack traffic exists in the user behavior sequence, the user behavior sequence is input into a pre-trained generation model, and a network kill chain corresponding to the attack traffic is generated based on the generation model.

2. The method according to claim 1, characterized in that Before generating multi-source logs and security warning logs according to network traffic and terminal behavior, it also includes: Input any multi-source log data into the large model for pre-training to obtain the first large model; A classification layer is added to the first large model to obtain a second large model, and the first sample log data set is input into the second large model for training to obtain the detection model, wherein the first sample log data set is a collection of associated multi-source log data arranged and spliced ​​in time sequence and carrying labels, the associated multi-source log data is all log data associated with the same user, and the label is an attack traffic label or a normal traffic label; The second sample log data set is input into the first large model for training to obtain the generation model that outputs the text description of the network kill chain, wherein the second sample log data set is a collection of associated multi-source log data arranged and spliced ​​in time sequence and carrying the attack traffic label.

3. The method according to claim 1, characterized in that The obtaining of the user behavior sequence by associating the multi-source logs based on the aggregated security alarm log comprises: Associating the aggregated security alarm log with the multi-source log to obtain all log data; Obtain all behavior records of the same user from all the log data; Arrange all the behavior records in chronological order to obtain the user behavior sequence.

4. The method according to claim 1, characterized in that The original logs of different device ends include network side logs, terminal side logs and service logs.

5. The method according to claim 1, characterized in that The network kill chain includes the attacker's intrusion path, attack means and attack target.

6. A device for generating a network kill chain, characterized in that: The device comprises: A first generation module generates multi-source logs and security warning logs according to network traffic and terminal behavior, wherein the multi-source logs are original logs of different device terminals; A log association module, which aggregates the security alarm log to obtain an aggregated security alarm log, and associates the multi-source logs based on the aggregated security alarm log to obtain a user behavior sequence, wherein the user behavior sequence is a sequence in which the behavior records generated by the same user on the different device terminals are arranged in time sequence; An attack detection module, inputting the user behavior sequence into a pre-trained detection model, and detecting whether there is attack traffic in the user behavior sequence based on the detection model; The second generation module, when attack traffic exists in the user behavior sequence, inputs the user behavior sequence into a pre-trained generation model, and generates a network kill chain corresponding to the attack traffic based on the generation model.

7. The device according to claim 6, characterized in that The device is also used for: Input any multi-source log data into the large model for pre-training to obtain the first large model; A classification layer is added to the first large model to obtain a second large model, and the first sample log data set is input into the second large model for training to obtain the detection model, wherein the first sample log data set is a collection of associated multi-source log data arranged and spliced ​​in time sequence and carrying labels, the associated multi-source log data is all log data associated with the same user, and the label is an attack traffic label or a normal traffic label; The second sample log data set is input into the first large model for training to obtain the generation model that outputs the text description of the network kill chain, wherein the second sample log data set is a collection of associated multi-source log data arranged and spliced ​​in time sequence and carrying the attack traffic label.

8. The device according to claim 6, characterized in that The log association module is specifically used for: Associating the aggregated security alarm log with the multi-source log to obtain all log data; Obtain all behavior records of the same user from all the log data; Arrange all the behavior records in chronological order to obtain the user behavior sequence.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to implement the method steps of any one of claims 1 to 5 when executing the computer program stored in the memory.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Threat detection method, device and equipment and storage medium

    CN111147504A

  • Police cloud security data fusion method, system and device and storage medium

    CN115277177A

  • Attack path modeling method and system based on multi-source alarm log compression

    CN116614245A

  • Attack investigation method based on host log serialization analysis

    CN117009048A

  • Method and device for generating network killing chain and electronic equipment

    CN117395072A

Cited By

  • Abnormal behavior detection method and device based on AI and storage medium

    CN120546997A

  • Security log analysis system, method and equipment based on AI large model and medium

    CN120934854A

  • Multi-agent driven safety alarm log simulation generation method

    CN121098738A