The application provides an
attack homologous
analysis method,
system,
electronic equipment and storage medium, and relates to the technical field of
network security. The method comprises the following steps: obtaining event clues, alarm data and sample data of a to-be-tested
attack event; extracting ATT&CK tactics and technology features from the alarm data, extracting sample HASH values and code features from the sample data, and extracting
attack industry and country features from the event clues; respectively calculating the similarity between the extracted features and corresponding features in a preset APT organization feature
library; calculating a comprehensive similarity
score based on each similarity, and determining the homologous APT organization of the to-be-tested attack event according to the comprehensive similarity
score. The application integrates multiple-dimensional data sources, breaks through the analysis blind area caused by a single
data source, simultaneously fuses static code and dynamic alarm features, effectively overcomes the
false alarm problem caused by incomplete
confusion code disassembly, and significantly improves the accuracy, comprehensiveness and robustness of attack tracing and homologous identification.