面向安全事件的威胁情报汇聚方法
网络出版日期: 2024-07-16
基金资助
国家自然科学基金(62376265)
版权
A threat intelligence aggregation method for security events
Online published: 2024-07-16
Copyright
随着网络安全威胁的不断演进,国内外安全企业纷纷建立了自己的威胁情报平台并提供服务。尽管业界制定了多种威胁情报的标准和规范以促进信息共享,但由于信任、隐私保护、利益分配等问题,实际的共享效果并不理想。针对现有威胁情报共享中存在的问题,提出了一种基于安全事件的威胁情报汇聚方法。该方法利用事件的语义特性重组威胁情报,简化了表达结构,提高了结构化程度,并利用改进的骨架法实现了模型的半自动化构建,提升了构建效率和形式化水平。将构建的威胁情报模型应用于大模型技术的训练与推演,可以有效支持未知情报的挖掘与安全事件的告警。本研究不仅为威胁情报的汇聚和共享提供了新的方法,也为网络安全防御能力的提升贡献了新思路。
赵洋 , 王鹏 , 于旸 , 翟立东 . 面向安全事件的威胁情报汇聚方法[J]. 网络空间安全科学学报, 2024 , 2(2) : 56 -65 . DOI: 10.20172/j.issn.2097-3136.240205
As cyber threats continue to evolve, security enterprises both domestically and internationally have established their own threat intelligence platforms and provided services. Despite various standards and specifications proposed in the industry to facilitate information sharing, issues such as trust, privacy protection, and the distribution of benefits have hindered effective collaboration. Addressing the existing challenges in threat intelligence sharing, a threat intelligence aggregation method based on security events was proposed. This method reorganized threat intelligence by leveraging the semantic properties of events, simplifying the expression structure, and enhancing the level of structuration. Additionally, an improved skeleton method was utilized to achieve semi-automated model construction, thereby increasing construction efficiency and formalization. Applying the developed threat intelligence model to large-scale model training and simulation could effectively support the mining of unknown intelligence and the alerting of security events. This research not only offers a novel approach to the aggregation and sharing of threat intelligence but also contributes new ideas for enhancing cybersecurity defense capabilities.
表 1 事件维度的情报信息Table 1 Event-based intelligence information |
| 事件要素 | 要素说明 | 内容示例 |
| 主体要素 | 攻击者身份信息、所属组织信息、国家信息 | APT 29 |
| 时间要素 | 单次攻击的发生时间; 多次攻击的时间规律; 预测攻击的发生时间和概率 | 2022/5/12 22:00:23 GMT +08:00; 30天内频繁发起DOS攻击; 30天内对某类资产发起攻击的概率为70% |
| 地点要素 | 攻击者的网络地址(池); 攻击者的物理地址 | 网络地址:10.10.10.10; 物理地址:XX国家XX省(州)XX市 |
| 客体要素 | 目标资产; 资产所属方信息 | Windows 7 PC主机; XX公司 |
| 动机要素 | 攻击目的 | 致瘫致毁、数据窃取、远程控制 |
| 动作要素 | 行为类型 | 正常访问、确定攻击、可疑访问 |
| 方法要素 | 攻击手段 | 利用“永恒之蓝”漏洞发起勒索攻击 |
| 结果要素 | 影响程度;可信程度 | 严重影响、轻微影响、无影响; 以概率表示可信程度 |
| 应对要素 | 预防措施、处置建议 | 尽快更新补丁或升级到更高版本Windows系统 |
表 2 基于事件的威胁情报应用本体Table 2 Event-based threat intelligence application ontologies |
| 事件类 | 子类 | 属性 | 描述 |
| 攻击者 | — | 名称 | 攻击者的名称或代号信息 |
| — | 类型 | 个人、组织 | |
| — | 所属国家 | 攻击者所属国家 | |
| 时间 | — | 类型 | 单次攻击发生时间、多次攻击发生时间规律、未发生攻击时间预测 |
| — | 时间点 | 单次攻击发生时间、预测发生时间 | |
| 地点 | — | 网络位置 | 攻击者使用的IP地址 |
| — | 地理位置 | 攻击者所处的地理位置 | |
| — | 地点规律 | 用于描述非独立事件 (如由同一攻击者发起的多个同类攻击事件)的地点规律,多点并发 | |
| 攻击对象 | 资产 | 名称 | 资产的具体名称,如Windows 7 PC |
| 类型 | 硬件、链路、服务、数据 | ||
| 版本 | 目标资产对应的版本信息 | ||
| 资产所属方 | 类型 | 个人、组织 | |
| 名称 | 个人、组织的名称 | ||
| 所属国家 | 个人、组织所属国家 | ||
| 攻击类型 | — | 类型 | 正常访问、确定攻击、可疑访问 |
| — | 编号 | STIX中描述的可观测行为的编号 | |
| 攻击动机 | — | 战术目标 | 在战术层面达成的攻击目标,如致瘫致毁、数据窃取、控制 |
| — | 战略目标 | 在战略层面达成的攻击目标,如展示实力、政治目的 | |
| 攻击方式 | Killchain模型 | 阶段 | Killchain模型描述的7个阶段 |
| ATT&CK模型 | 编号 | ATT&CK中描述的攻击战技术的编号 | |
| Vulnerability | 编号 | 所使用的漏洞CVE编号 | |
| Tool | 名称 | 所使用的工具名称 | |
| 攻击结果 | — | 影响度 | 本次攻击事件的严重程度和造成的影响程度,0代表无影响,1代表轻微影响,2代表中等影响, 3代表严重影响 |
| — | 可信度 | 本条攻击事件情报信息的可信度,0~1之间的连续值,0代表可信度最低,1代表可信度最高 | |
| 应对措施 | — | 编号 | 采取的应对措施代号 |
| 描述 | 对该应对措施的描述,如打补丁、备份重要文件 |
表 3 威胁情报相关本体比较Table 3 Comparison of threat intelligence topologies |
| 组件 | 本文本体 | MALOnt 2.0 | TAL | 威胁情报本体 |
| 威胁主体类型 | √ | √ | √ | √ |
| 威胁主体经验 | √ | √ | ||
| 发生时间 | √ | √ | ||
| 影响资产 | √ | √ | ||
| 安全事件状态 | √ | |||
| 威胁主体动机 | √ | √ | ||
| 攻击行为 | √ | √ | √ | |
| 影响评估 | √ | |||
| 可信度 | √ | |||
| 应对措施 | √ | √ | ||
| 可观测数据 | √ | √ | √ | |
| 攻击阶段 | √ | √ | ||
| 相关攻击方式TTP | √ | √ | √ | |
| 信息来源 | √ | √ | ||
| 攻击资源 | √ | |||
| 相关漏洞 | √ | √ | √ |
表 4 安全事件相关本体比较Table 4 Comparison of security events topologies |
| 要素 | 本文本体 | 计算机安全 事件本体 | 入侵检测 本体 | 网络攻击案例 本体 |
| 事件发生时间 | √ | |||
| 事件发生地点 | √ | |||
| 攻击者 | √ | √ | √ | |
| 受害者 | √ | √ | √ | |
| 攻击方式 | √ | √ | √ | √ |
| 攻击结果 | √ | √ | √ | √ |
| 应对措施 | √ | √ | ||
| 输入方式 | √ | |||
| 攻击动机 | √ | √ | ||
| 攻击行为 | √ | √ |
| 1 |
KARATISOGLOU M,FARAO A,BOLGOURAS V,et al. BRIDGE:bridging the gap between CTI production and consumption[C]//2022 14th International Conference on Communications (COMM). IEEE,2022:1-6.
|
| 2 |
CHEN J F, FAN H B. Ontological threat intelligence sharing in cyberspace security[J]. Communications Technology, 2018, 51 (1): 177- 183.
|
| 3 |
MCMILLAN R,PRATAP K. Market guide for security threat intelligence service(G00259127)[R]. Stamford,CT:Gartner Inc. ,2014.
|
| 4 |
FRIEDMAN J,BOUCHARD M. Definitive guide to cyber threat intelligence:using knowledge about adversaries to win the war against targeted attacks[M]. Annapolis,MD:Cyber Edge Group,2015.
|
| 5 |
TOUNSI W,RAIS H. A survey on technical threat intelligence in the age of sophisticated cyber attacks[J]. Computers and Security,2018,72:212-233.
|
| 6 |
崔琳, 杨黎斌, 何清林, 等. 基于开源信息平台的威胁情报挖掘综述[J]. 信息安全学报, 2022, 7 (1): 1- 26.
CUI L, YANG L B, HE Q L, et al. Survey of cyber threat intelligence mining based on open source information platform[J]. Journal of Cyber Security, 2022, 7 (1): 1- 26.
|
| 7 |
杨沛安, 武杨, 苏莉娅, 等. 网络空间威胁情报共享技术综述[J]. 计算机科学, 2018, 45 (6): 9- 18,26.
YANG P A, WU Y, SU L Y, et al. Overview of threat intelligence sharing technologies in cyberspace[J]. Computer Science, 2018, 45 (6): 9- 18,26.
|
| 8 |
CHISMON D,RUKS M. Threat intelligence:collecting,analysing,evaluating[R]. MWR Info., Security Ltd.,2015.
|
| 9 |
高见, 王安. 基于本体的网络威胁情报分析技术研究[J]. 计算机工程与应用, 2020, 56 (11): 112- 117.
GAO J, WANG A. Research on ontology-based network threat intelligence analysis technology[J]. Computer Engineering and Applications, 2020, 56 (11): 112- 117.
|
| 10 |
CHRISTIAN R,DUTTA S,PARK Y,et al. An ontology-driven knowledge graph for Android malware[C]//Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2021:2435-2437.
|
| 11 |
YEBOAH-OFORI A,ISMAIL U M,SWIDURSKI T,et al. Cyberattack ontology:a knowledge representation for cyber supply chain security[C]//2021 International Conference on Computing,Computational Modelling and Applications (ICCMA). IEEE,2021:65-70.
|
| 12 |
SÁNCHEZ-ZAS C, VILLAGRÁ V A, VEGA-BARBAS M, et al. Ontology-based approach to real-time risk management and cyber-situational awareness[J]. Future Generation Computer Systems, 2023, 141, 462- 472.
|
| 13 |
SYED R. Cybersecurity vulnerability management: a conceptual ontology and cyber intelligence alert system[J]. Information & Management, 2020, 57 (6): 103334.
|
| 14 |
ZHAO Y ,LANG B ,LIU M . Ontology-based unified model for heterogeneous threat intelligence integration and sharing[C]// 2017 11th IEEE International Conference on Anti-counterfeiting,Security,and Identification,IEEE,2017:21-25.
|
| 15 |
李文雄,武东英,刘胜利,等. 基于本体的网络攻击案例库模型研究[J]. 计算机科学,2014,41(10):173-176+195.
LI W X,WU D Y ,LIU S L,et al. Research on cyber attack case base model based on onotology[J]. Computer Science,2014,41(10):173-176+195.
|
| 16 |
MERAH Y,KENAZA T. Ontology-based cyber risk monitoring using cyber threat intelligence[C]//Proceedings of the 16th International Conference on Availability,Reliability and Security. 2021:1-8.
|
| 17 |
WEI X,CUI X,CHENG N,et al. Zero-shot information extraction via chatting with ChatGPT[EB]. arXiv preprint arXiv:2302. 10205,2023.
|
| 18 |
GE B,ZHENG W,YANG G M,et al. Microblog topic mining based on a combined TF-IDF and LDA topic model[M]//Automatic Control,Mechatronics and Industrial Engineering. Leiden:CRC Press,2019:291-296.
|
| 19 |
LINDIG C. Fast concept analysis[C]//Working with Conceptual Structures-Contributions to ICCS. 2000:152-161.
|
| 20 |
MAVROEIDIS V,HOHIMER,CASEY T,et al. Threat actor type inference and characterization within cyber threat intelligence[C]//2021 13th International Conference on Cyber Conflict (CyCon). IEEE,2021:327-352.
|
| 21 |
全国信息安全标准化技术委员会. 信息安全技术 网络安全威胁信息格式规范:GB/T 36643-2018[S]. 北京:中国标准出版社,2018.
National Technical Committee 260 on Cybersecurity Standardization Administration of China. Information security technology Cybersecurity threat information format specification:GB/T 36643-2018[S]. Beijing:Standards Press of China,2018.
|
| 22 |
The phantom that wanders the Middle East - analysis of recent attack activity by APT group Arid Viper[EB/OL]. (2022-11-26)[2024-04-06]. https://www.uu11.com/keji/690217.html.
|
| 23 |
The MITRE Corporation. ATT&CK matrix for enterprise[EB/OL]. (2022-10-25)[2024-04-06]. https://attack.mitre.org/.
|
/
| 〈 |
|
〉 |