The invention discloses an APT
attack traceability graph construction method based on a dynamic sliding window and multi-dimensional
time sequence scoring. The method comprises the following steps: collecting multi-source heterogeneous
system audit
log data, analyzing the multi-source heterogeneous
system audit
log data into a standardized entity interaction tetrad flow, and constructing a continuous
time sequence evolution dynamic
traceability graph snapshot through a sliding window mechanism; in order to solve the problems that an existing total
traceability graph causes scale explosion along with long-term operation of a
system and a traditional statistical
pruning method is prone to losing low-frequency key
attack semantics, topological connection strength of nodes,
time sequence burstiness of interaction frequency and causal association with
threat intelligence are utilized, and the probability of low-frequency key
attack semantics is lowered. A three-dimensional lightweight scoring model is constructed to quantify node values, and a safety
anchor point mechanism is introduced for forced retention for high-risk nodes hitting
threat intelligence or key assets, so that the high-risk nodes are prevented from being rejected as
noise due to relatively
low frequency; and for other background nodes, an exponential
moving average algorithm is utilized to capture behavior burst characteristics and perform dynamic Top-K
pruning, system interaction with high information content is reserved while denoising is performed, and finally a traceability
graph sequence considering scale simplification and semantic completeness is generated. According to the method provided by the invention, the key
semantic information of the APT attack can be effectively reserved while the data scale and the calculation overhead are greatly reduced.