Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

47 results about "Kill chain" patented technology

The term kill chain was originally used as a military concept related to the structure of an attack; consisting of target identification, force dispatch to target, decision and order to attack the target, and finally the destruction of the target. Conversely, the idea of "breaking" an opponent's kill chain is a method of defense or preemptive action. More recently, Lockheed Martin adapted this concept to information security, using it as a method for modeling intrusions on a computer network. The cyber kill chain model has seen some adoption in the information security community. However, acceptance is not universal, with critics pointing to what they believe are fundamental flaws in the model.

Method and device for constructing and recommending equipment system adversarial network of dynamic time sequence event

The invention discloses a dynamic time sequence event equipment system adversarial network construction and recommendation method and device, and relates to the field of killing network design, and the method comprises the steps: constructing an initial detection-command and control-strike warning network; a dynamic time sequence event on the battlefield is continuously monitored, when the event type of the dynamic time sequence event is an equipment state event, the initial detection-command-strike warning network is updated, and when the event type of the dynamic time sequence event is a chained event, a closed detection-command-strike link set containing an enemy target is generated; the closed detection-command-strike link set comprises a plurality of killing chains; based on the multi-dimensional evaluation index system, evaluating each killing chain to obtain an evaluation result corresponding to each killing chain; and according to the evaluation results corresponding to all the killing chains, recommending an optimal interception scheme of an air defense and anti-guide interception action. The method overcomes the problems of large calculation dimension and slow response speed of an existing method.
Owner:BEIJING INST OF TECH

Security event tracing system and method based on attack chain analysis

The invention discloses a security event traceability system and method based on attack chain analysis, relates to the technical field of data security protection, and is used for realizing multi-level perception of attack activities by building a multi-modal killing chain probe matrix as a structured data basis. Modeling analysis is carried out on attack behaviors of different levels through a deep heterogeneous feature extraction architecture, multi-dimensional features are fused into a cross-layer joint feature vector, a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector, the propagation path and probability of APT attack are simulated, a high-dimensional attack curved surface is drawn, and a 3D attack deduction sand table is constructed according to the cross-layer joint feature vector. And key path nodes and potential transverse diffusion directions are identified, and a defense strategy knowledge graph is constructed according to a modeling result. The traceability system breaks through barriers among threat detection, attack understanding and defense response through a stage linkage mode of'probe sensing-intention recognition-path modeling-defense deduction ', and realizes accurate traceability and efficient disposal of security events.
Owner:SHANGRAO DAWAN NETWORK TECHNOLOGY CO LTD

Security method for identifying kill chains

A computer implemented security method security method is described, for detecting attacks on a system or network. The method comprises defining a sequence of attack tactics, each attack tactic representing a generalisation of a set of attack techniques, associating one or more attack detection rules with each of the attack techniques, detecting attack events based on the attack detection rules, correlating the detected attack events with the attack tactics based on the attack technique associated with the attack detection rule used to detect the attack events, linking the detected attack events based on one or more criteria, and identifying one or more paths of attack techniques through the sequence in dependence on the linked attack events. The identified paths of attack techniques represent kill chains. The present technique makes it possible to identify new kill chains of known techniques, as well as making it possible to identify high-risk kill chains.
Owner:BRITISH TELECOM PLC

Service-based killer chain analysis construction method

The invention discloses a service-based killer chain analysis construction method, which belongs to the technical field of cooperative combat, and comprises the following steps: constructing a service resource pool, and setting a service discovery mechanism; on the basis of the fusion situation set, a situation switching event is recognized so as to perform local updating, and a three-level situation view is constructed; constructing a directed hyperedge, generating a directed hypergraph in combination with function category constraints, generating a dimensionality reduction state space based on multi-dimensional constraints, and generating an initial combat candidate set; configuring a management node, sending task invitation information to the initial combat candidate set in combination with the subtasks, generating a response scheme, performing adaptive screening, generating an initial killing chain, and performing failure verification; constructing a servitization twinborn body, deducing the initial killing chain, and executing delay at a calculation end so as to perform elimination recombination or delay optimization; a service combination template is constructed, an efficiency feedback mechanism is established, the superposition influence of frequent situation switching and state space catastrophe is cooperatively solved, and the real-time performance of generation of the killing chain is remarkably improved.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Multi-scale fusion network performance evaluation method based on killer chain driving

The invention discloses a multi-scale fusion network efficiency evaluation method based on killing chain driving, and the method employs the bottom-up idea of a complex system, considers the three-in-one condition of confrontation, dynamic and overall structure based on the incidence relation of nodes, a killing chain and a killing network, and carries out the evaluation of the efficiency of a multi-scale fusion network. An evaluation model from a micro scale to a middle scale and then to a macro scale is constructed, and the feasibility of the method is verified by comparing network efficiencies of tactical-level command systems with different architecture forms through simulation. By using the method, the integrality, the dynamic nature, the antagonism and the uncertainty characteristics of the network are comprehensively considered, and efficiency evaluation can be performed on the network in different environments. The method can be widely applied to the field of network performance evaluation.
Owner:SUN YAT SEN UNIV

Unmanned aerial vehicle cluster survivability evaluation method based on killing chain

The invention discloses an unmanned aerial vehicle cluster survivability evaluation method based on a killing chain, and relates to the technical field of unmanned combat system evaluation, and the method comprises the following steps: S1, summarizing the types and number of our unmanned aerial vehicles, forming a our unmanned aerial vehicle equipment list, and collecting enemy target information, and forming an enemy target list; s2, according to the communication relationship between the unmanned aerial vehicle clusters, analyzing the network topology structure of the unmanned aerial vehicle cluster combat, eliminating invalid network communication modes and enemy target nodes, and forming a directed unmanned aerial vehicle cluster survivability analysis network graph D = lt; e, Vgt; . According to the unmanned aerial vehicle cluster survivability evaluation method based on the killing chain, different unmanned aerial vehicle nodes are destroyed, the comprehensive survivability evaluation value change of the whole unmanned aerial vehicle cluster is calculated, a survivability change trend chart is drawn, and key equipment nodes and weak links which have the largest influence on network survivability are judged.
Owner:CHINA ORDNANCE SCI INST

Cps attack path reconstruction method and system based on kill chain model clustering

The application belongs to the technical field of network security, and particularly relates to a CPS attack path reconstruction method and system based on a kill chain model clustering. CPS information layer and physical layer operation data are collected, a feature vector is generated through time window fusion, a feature subspace is divided based on the four stages of the kill chain, candidate clusters are obtained by clustering the data of each stage, high-confidence clusters are screened in combination with time concentration and behavior intensity, a causal diagram is constructed according to time proximity and cross-layer correlation, and complete reconstruction of the attack path is realized; the application adapts to the cross-layer coupling characteristics of CPS, improves the accuracy of attack stage division and path reconstruction, and can provide reliable support for attack tracing and defense strategy formulation.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

Asset remediation trend map generation and utilization for threat mitigation

The present disclosure relates to methods, systems, and computer program products for generating an asset remediation trend map used in remediating against an attack campaign. The method comprises receiving attack kill chain data. The attack kill chain data comprises steps for executing an attack campaign on one or more assets associated with a computing device. The method further comprises parsing the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device. The method determines based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations. In addition, the method sequences the one or more remediation operations to form an asset remediation trend map. In one implementation, the asset remediation trend map indicates steps for remediating the attack campaign.
Owner:QUALYS

Threat activity statistical analysis driven adaptation of a control specification

Threat activity statistical analysis driven adaptive control specification includes retrieving a data structure from over a computer communications network into memory of a computing device and parsing the data structure in the memory to extract a listing of different threat activities. Threat activity statistical analysis driven adaptive control specification also includes computing in the memory a statistical analysis of the different threat activities. Finally, threat activity statistical analysis driven adaptive control specification includes responding to the statistical analysis surpassing a threshold for an identified one of the different threat activities by determining a corresponding threat incorporating the identified one of the different threat activities in an associated kill chain, retrieving a control specification addressing the corresponding threat, and modifying the control specification to address changes in the corresponding threat.
Owner:HITRUST SERVICES LLC

A service-based kill chain analysis construction method

The application discloses a kind of service-based kill chain analysis construction methods, belong to the technical field of cooperative combat, including: constructing service resource pool, and set service discovery mechanism;Based on fusion situation set, identify situation switching event, to carry out local update, and construct three-level situation view;Directed hyperedge is constructed, combined with function category constraint, generates directed hypergraph, generates dimensionality reduction state space based on multidimensional constraint, and generates initial combat candidate set;Configuration management node, combined with subtask to the initial combat candidate set sends task invitation information, generates response scheme and carries out adaptation screening, generates initial kill chain, and carries out failure check;Build service twin, deduce the initial kill chain, calculate end execution delay, to carry out elimination reorganization or delay optimization;Build service combination template, and establish efficiency feedback mechanism, cooperatively solve the superimposed influence of frequent situation switching and state space catastrophe, significantly improve kill chain generation real-time performance.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Detection of multi-killchain alerts

A method for the detection of multi-killchain alerts is disclosed. The method includes receiving, by a computer system, a plurality of alerts indicative of activity within a computer network, wherein a given alert specifies one or more events having attributes, and extracting attributes from events included in the plurality of alerts. The method further includes determining attribute similarity for pairs of events based on whether a given pair of events has common values for one or more attributes and whether attribute values of the given pair of events indicates lateral movement within computers of the computer network. Linked pairs are then identified based on the determined attribute similarity and added to a graph data structure. The method further includes the computer system analyzing the graph data structure to find clusters of events relating to a security attack.
Owner:SALESFORCE INC

Context-aware security policies and incident identification via automated cloud graph building with security overlays

Context-aware security policies and incident identification, via automated cloud graph building with security overlays, are determined and performed by systems and platforms. Graph nodes, of a graph associated with a computing system, that represent resources associated with the computing system and entities associated with the computing system that have respective associations to the resources are generated. Security attributes are determined and assigned to the graph nodes that represent the entities and resources, and static and dynamic connections between the graph nodes are added to the graph. Additionally, possible connections in the graph between the graph nodes are added based on heuristic relational determinations of the graph nodes. From the graph, security incidents and kill chains are identified, context-aware security policies are generated and validated, and scopes and relationships of applications are identified. Accordingly, security actions are taken for the computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A General Complex Network Attack Inference Method Based on Bayesian ATT&CK Network

The present invention discloses a general complex network attack inference method based on the Bayesian ATT&CK network, which relates to the field of network security technology. Using the kill chain and empirical knowledge as the research basis, it conducts a temporal logic modeling of the tactics in the ATT&CK framework to ensure that the generated attack sequences are logically coherent and reflect the behavior patterns of real complex network attacks; based on the tactical temporal logic sequence, it extends the guidance of expert knowledge on tactical transfer to the guidance of technique transfer, and constructs a technique dependency network; it uses an anonymized dataset from real network attack events and further optimizes the technique dependency network by utilizing the co-occurrence relationship of techniques in the dataset; based on the technique dependency network and the co-occurrence relationship of techniques in the real network attack dataset, the Bayesian ATT&CK network performs structure learning and parameter learning to construct a network model independent of specific threat detection systems, realizing the inference of complex network attacks independent of specific systems.
Owner:BEIHANG UNIV

Method for quickly and dynamically reconstructing ultra-long-distance air-to-air killer chain

The invention discloses a method for quickly and dynamically reconstructing an ultra-long-distance air-to-air killing chain, belongs to the technical field of ultra-long-distance air-to-air killing chains, and realizes dynamic recombination of the killing chain by using a self-organizing iterative clustering algorithm. In the execution process of the killing chain, if a reconstruction condition is triggered, all the combat platforms in normal operation are divided into six clusters according to the execution stages of discovery, positioning, tracking, aiming, combat and evaluation, each cluster is divided into different groups according to different loads loaded by the combat platforms, and the loading loads comprise ESM, light thunder and radar; for the combat platforms loaded with the same load, dividing the combat platforms in the same area into the same cluster by taking the current position as a division condition; all the combat platforms are subjected to dimension reduction clustering in sequence. According to the method, the high-dimensional complex calculation degree generated in the killer chain reconstruction process is subjected to dimension reduction processing, the calculation amount is remarkably reduced, and the reconstruction time is shortened.
Owner:NORTHWESTERN POLYTECHNICAL UNIV +1

Anti-killer chain construction method based on service-oriented killer chain

The invention relates to the technical field of killer chain construction, in particular to an anti-killer chain construction method based on a service-oriented killer chain, and provides the following scheme: target motion prediction is performed based on real-time state information of a to-be-hit target to obtain a predicted path of the target in a preset time, and a probability cloud model is constructed in a three-dimensional tactical space to obtain a predicted path of the target; and a target influence area is determined after tactical environment constraint correction. And screening candidate service objects from the service resource library according to space, time and capability constraints, and mapping the candidate service objects to each killing chain link in combination with the service type killing chain template corresponding to the target. According to the method, rapid reconstruction of the killing chain can be realized under the conditions of target maneuvering, equipment damage or resource replacement, and the flexibility and continuous strike capability of a combat system are improved.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

CPS attack path reconstruction method and system based on killer chain model clustering

The invention belongs to the technical field of network security, and particularly relates to a CPS attack path reconstruction method and system based on killer chain model clustering. The method comprises the steps of collecting operation data of a CPS information layer and a physical layer, generating feature vectors through time window fusion, dividing feature subspaces based on four stages of a killing chain, clustering data of each stage to obtain candidate clusters, screening high-credibility clusters in combination with time concentration and behavior intensity, and constructing a causal graph according to time proximity and cross-layer correlation. Complete reconstruction of an attack path is realized; the method adapts to CPS cross-layer coupling characteristics, improves the accuracy of attack stage division and path reconstruction, and can provide reliable support for attack traceability and defense strategy formulation.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

Urban unmanned aerial vehicle defense-oriented disposal strategy automatic generation system

The invention discloses an urban unmanned aerial vehicle defense-oriented disposal strategy automatic generation system, and the system comprises an initialization module which is used for carrying out initialization; the situation information updating module is used for continuously receiving the situation information and instantiating the incoming target; the killing network construction module is used for sequentially calculating a connection relationship among a target node, an interception equipment node and a detection equipment node in the killing network to form the killing network; the killing chain optimization module is used for monitoring the integrity of the killing chain where each target is located and maintaining the original killing chain or regenerating the killing chain according to the monitoring result; and the self-evolution module is used for realizing iterative optimization updating of artificial neural network parameters in the killing chain optimization module by accumulating actual combat data and a reinforcement learning method, so that the model generates a better unmanned aerial vehicle disposal strategy. According to the technical scheme, the problem that the killing chain is interrupted due to factors such as building shielding in the urban environment can be solved, and rapid and effective maintenance of the killing network based on the real-time situation is ensured.
Owner:JIANGNAN ELECTROMECHANICAL DESIGN INST +1

A method for generating kill chains and recommending remediation action

A method includes, for each vulnerability in a set of vulnerabilities: deriving a correlation between the vulnerability and an attack technique based on language signals detected in descriptions of the vulnerability; constructing a vulnerability module defining the attack technique and representing the vulnerability; detecting a second vulnerability preceding exploitation of the vulnerability in the corpus of threat intelligence; defining the second vulnerability as an input vulnerability in the vulnerability module; detecting a third vulnerability succeeding exploitation of the vulnerability in the corpus of threat intelligence; defining the third vulnerability as an output vulnerability in the vulnerability module; interpreting an access tier of the vulnerability based on characteristics of the attack technique; accessing a vulnerability risk score for the vulnerability; interpreting a mitigation technique for the attack technique; and annotating the vulnerability module with the access tier, the vulnerability risk score, and the mitigation technique.
Owner:TEGULA LLC

Sensor-to-shooter kill chain decision system apparatus and method

A sensor-to-shooter kill chain decision system (KCDS) provides a human machine interface (HMI) that reduces the cognitive burden associated with processing battlefield environment information and enhances the ability for lethal decision making in reduced time periods.
Owner:ARES TECHNOLOGY LLC

Systems and methods for countering persistent malware

Some embodiments construct an entity map describing a group of inter-related entities and determine whether a computing device comprises malware according to the respective entity map. The entity map includes worker entities (e.g., processes) and resource entities (e.g., files) accessed by the respective worker entities. Some entity maps are persistently stored and recovered in response to a reboot, enabling a complete reconstruction of a kill chain even when malicious activities are distributed among multiple entities and multiple computing sessions. Some embodiments detect infection by comparing a current entity map with a signature map describing at least a fragment of a known attack.
Owner:BITDEFENDER IPR MANAGEMENT

A causal reasoning-based APT kill chain reconstruction and prediction method and system

The present invention relates to the technical field of APT kill chain reconstruction and prediction methods, and provides an APT kill chain reconstruction and prediction method and system based on causal reasoning. The method aims to address the problems existing in existing APT detection and defense technologies, such as difficulty integrating multi-source heterogeneous data, insufficient spatiotemporal dynamic feature modeling, inaccurate kill chain reconstruction, limited predictive capabilities, poor interpretability, and difficulty balancing real-time and accuracy. The method comprises acquiring multi-source heterogeneous data, constructing a causal graph, performing multimodal feature extraction based on the causal graph to obtain initial node feature representations; inputting the initial node feature representations into a temporal causal graph convolutional learning algorithm to obtain optimized node representations; performing kill chain reconstruction based on the optimized node representations to obtain possible kill chain sequences; predicting future attack paths based on the possible kill chain sequences to obtain potential attack paths; and generating an interpretable analysis report based on the potential attack paths.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Optimization Method for Weapon and Equipment Deployment Points Driven by Rapid Closure of the Kill Chain

An optimization method for the deployment points of weapon and equipment driven by the rapid closure of the kill chain, which relates to the field of equipment technology. Aiming at the problem of slow speed in generating the deployment point information of weapon and equipment in the existing technology, this application first constructs a kill chain model for specific tasks based on the correlation relationships among various pieces of equipment involved in the system confrontation process; then, according to the node information of the weapon and equipment to be optimized, the node positions are optimized through the proposed new large-scale multi-objective evolution method; finally, the kill chain formed by the optimized weapon and equipment has a fast closure speed, high connectivity, and strong network connectivity importance. For the combat system in offensive and defensive confrontation, the rapid closure of the kill chain needs to simultaneously possess a fast closure speed, high connectivity, and strong network connectivity importance. The application of this application can quickly generate the deployment point information of weapon and equipment with a rapid kill chain closure.
Owner:HARBIN INST OF TECH

Kill chain identifications

An example storage medium stores instructions that, when executed, cause a processor of a computing device to receive an indication associated with a first virtual machine, the first virtual machine containing a first application, the indication indicating that a first operation in the first virtual machine is to use a second application; receive information associated with a second virtual machine, the second virtual machine created in response to the first operation and containing the second application; store information describing a chain of virtual machines, the chain of virtual machines including the first and second virtual machines, the stored information including a relationship between the first virtual machine and the second virtual machine, based on the received indication and the received information; and in response to an identification of malware in the chain of virtual machines, identify a particular virtual machine in the chain of virtual machines that is in a kill chain of the malware based on the stored information.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

Systems and methods for countering persistent malware

Some embodiments construct an entity map describing a group of inter-related entities and determine whether a computing device comprises malware according to the respective entity map. The entity map includes worker entities (e.g., processes) and resource entities (e.g., files) accessed by the respective worker entities. Some entity maps are persistently stored and recovered in response to a reboot, enabling a complete reconstruction of a kill chain even when malicious activities are distributed among multiple entities and multiple computing sessions. Some embodiments detect infection by comparing a current entity map with a signature map describing at least a fragment of a known attack.
Owner:BITDEFENDER IPR MANAGEMENT

A dynamic kill chain construction and reconfiguration method and apparatus

The application discloses a dynamic killing chain construction and reconstruction method and device, which acquires real-time situation data and constructs a time-varying heterogeneous graph for representing a connection relationship of heterogeneous nodes and multi-dimensional constraints, performs phased searching in the time-varying heterogeneous graph based on a task demand, generates a candidate killing chain set containing a main chain and a backup chain, executes feasibility screening on the candidate killing chain set to eliminate chains that do not satisfy hard constraints and obtains a feasible chain set, then performs multi-objective collaborative optimization selection on the feasible chain set, outputs a backup chain set and a target main chain, and finally, when a node state change triggering a reconstruction condition is monitored, performs a hierarchical reconstruction operation based on the target main chain, the backup chain set and a time-varying heterogeneous graph updated in real time to generate an updated killing chain execution scheme.
Owner:BAIYANG TIMES (BEIJING) TECH CO LTD

A dynamic kill chain construction and reconfiguration method and apparatus

The application discloses a dynamic killing chain construction and reconstruction method and device, which acquires real-time situation data and constructs a time-varying heterogeneous graph for representing a connection relationship of heterogeneous nodes and multi-dimensional constraints, performs phased searching in the time-varying heterogeneous graph based on a task demand, generates a candidate killing chain set containing a main chain and a backup chain, executes feasibility screening on the candidate killing chain set to eliminate chains that do not satisfy hard constraints and obtains a feasible chain set, then performs multi-objective collaborative optimization selection on the feasible chain set, outputs a backup chain set and a target main chain, and finally, when a node state change triggering a reconstruction condition is monitored, performs a hierarchical reconstruction operation based on the target main chain, the backup chain set and a time-varying heterogeneous graph updated in real time, and generates an updated killing chain execution scheme.
Owner:BAIYANG TIMES (BEIJING) TECH CO LTD

Test method, device, storage medium and electronic equipment for satellite system security

Embodiments of the present disclosure provide a test method and device for satellite system security, a storage medium and an electronic device. The test method comprises: performing directional threat assessment on a composite kill chain of the satellite system to obtain a threat assessment result; performing threat deduction on a network space model of the satellite system to obtain a threat deduction result; and determining a defense action matrix based on the threat assessment result and the threat deduction result. Embodiments of the present disclosure construct a composite kill chain based on real-world real scenarios, effectively improve the defense coverage of the satellite system, enhance the security protection of the satellite system by determining potential threats that may exist in the satellite system, promote the improvement of the security countermeasure capability of the satellite system, form a benign mechanism and mature means that can be universally applied to the security protection deduction test of the satellite system of the army, and thus ensure the security of the satellite system under modern and future war conditions.
Owner:HARBIN ANTIY TECH

A Dynamic Defense Method and System for APT Network Kill Chain Based on Dual Deep Reinforcement Learning

A dynamic defense method and system for APT network kill chains based on dual deep reinforcement learning is proposed. The system pre-configures a network system including host nodes, security defenders, malicious attackers, and security defense devices. Malicious attackers execute attacks on host nodes according to the network kill chain. Security defenders monitor these attacks and acquire network status. Security defense devices, based on dual deep reinforcement learning algorithms and combined with the network status, dynamically generate optimal defense strategies and feed them back to the security defenders. The security defenders then dynamically respond to the attacks using these optimal strategies to protect against the network kill chain. This approach achieves efficient identification and accurate response to APT attacks, effectively improving system security and resource utilization efficiency. It provides an innovative solution for dynamic defense in complex network environments and significantly enhances the resistance to APT attacks.
Owner:XIAMEN UNIV

Killer chain construction method based on particle swarm optimization

The invention discloses a killing chain construction method based on a particle swarm algorithm, and belongs to the technical field of cooperative combat systems. The method comprises the following steps: dividing a killing chain construction problem into four links of detection, positioning, interference and strike which are executed in sequence, respectively establishing corresponding task allocation models, and taking maximization of efficiency of each link as a target function; and solving each link model by adopting an improved decimal discrete particle swarm algorithm to obtain an optimal task allocation scheme, and sequentially combining all link schemes to complete the construction of the killing chain. According to the method, the modeling process is simplified, the calculation efficiency is improved, the method is suitable for a large-scale combat scene, an optimization scheme can be quickly generated, and the requirements of actual combat for real-time performance and accuracy are effectively met.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Collaborative strategy-based killer chain construction method, apparatus and device, and medium

The invention provides a killing chain construction method and device based on a collaborative strategy, equipment and a medium. The killing chain construction method based on the collaborative strategy comprises the steps that target information of an attacking target is acquired through a UCN network; according to the network topology of the UCN network, the target information and a first constraint condition, determining a killing chain of the target to be attacked through a link selector by adopting a shortest path algorithm; according to the killing chain and a second constraint condition, carrying out resource processing on the platform of the UCN network by adopting a resource allocator to obtain a resource allocation result; and according to the killing chain and the resource allocation result, executing attack processing of the attack target through the UCN network. The device has the beneficial effects that the striking efficiency is improved, and the striking consumption is reduced.
Owner:NAT UNIV OF DEFENSE TECH