23-06-2023 дата публикации
Номер: CN116318929A
Принадлежит:
The invention relates to the technical field of network security, in particular to an attack strategy extraction method based on security alarm data. The method comprises the following steps: S1, acquiring single-step attack information of an attacker from an alarm text; s2, constructing an attack activity sequence set; s3, constructing a candidate attack strategy; s4, constructing an attack strategy data set; s5, pre-training is carried out; s6, model training; s7, extracting an attack strategy; and S8, carrying out manual verification. According to the method, whether a candidate attack strategy of an attacker is all effective attack steps or not is judged through a training model, and the attack purpose of the attacker can be completed through combination of the attack steps; through the model, all effective attack steps of an attacker can be associated in a candidate attack strategy enumeration mode, so that an attack strategy of the attacker is formed, and a large number of association ...
Подробнее