The invention discloses a mail
system advanced
threat traceability and detection method and
system based on a dynamic attribute graph, and relates to the technical field of
network security, and the technical scheme is characterized in that the method comprises the steps: collecting an operation log of a mail
server in real time, and extracting a standardized field; based on a predefined graph ontology, mapping a log entity into nodes such as a user, a
network address, a session, a resource and the like, mapping an operation behavior into a directed edge with a
timestamp and a weight, and constructing a dynamic
traceability graph; defining a malicious sub-graph topology template for a specific
attack mode; searching matched connected sub-graphs in real time in the
traceability graph by using a sub-graph isomorphic matching
algorithm; and when matching succeeds, generating an alarm and extracting a sub-graph as a traceability evidence. According to the method, discrete log behaviors are correlated through a
graph theory method, complex
attack behaviors such as
silence rule
thunder burying, parasitic account aggregation and geographical
kinetic energy abnormity can be effectively recognized, and the initiative and accuracy of mail security defense are remarkably improved.