首页|期刊导航|网络与信息安全学报|基于告警增量分析的攻击场景实时重构方法

基于告警增量分析的攻击场景实时重构方法OA

Real-time attack scenario reconstruction method based on incremental alert analysis

中文摘要英文摘要

面对日益复杂的多阶段、长周期网络攻击,安全事件常表现出跨时空域的交织关联.攻击场景重构能够有效支撑溯源取证和威胁发现,然而现有在攻击结束后基于全量告警数据分析的方法,存在结果滞后和效率低等问题.为此,针对告警信息的增量更新和全局视角存在矛盾问题,提出了基于时间窗口的增量式攻击场景重构方法.该方法的主要技术创新如下:①通过预处理和时间窗口划分,实现告警数据的规范化表达和分析规模的有效控制;②针对单窗口增量更新数据,以目标资产为中心构建攻击告警图并挖掘频繁1-项集,在此基础上通过图遍历策略生成并筛选所有可能攻击路径;③针对多个窗口的全局视角数据,提出一种攻击路径融合算法对已有路径和增量路径进行关联,实现攻击场景的全局重构.在开源和真实数据集上的实验结果表明,所提方法能够有效实现攻击场景重构,同时相比全量分析方法显著降低了计算复杂度,在增量场景下保持了稳定的处理性能.

In the face of increasingly complex multi-stage and long-term cyber attacks,security events often exhibit interconnections across both temporal and spatial domains.Attack scenario reconstruction plays a crucial role in supporting traceability,forensics,and threat discovery.However,existing methods that rely on analyzing full alert data after an attack has concluded suffer from issues such as delayed results and efficiency bottlenecks.To address the inherent tension between incremental alert updates and a global perspective,an incremental attack scenario re-construction method based on time window was proposed.The key technical innovations of the proposed method were as follows:①Through preprocessing and time-window partitioning,normalized representation of alert data was achieved while effectively controlling the analysis scale;②For incrementally updated data within a single win-dow,an attack alert graph was constructed centered on target assets as well as mining frequent 1-itemsets,followed by the use of a graph traversal strategy to generate and filter all possible attack paths;③For multi-window data from a global perspective,an attack path fusion algorithm was introduced to correlate historical paths with incre-mental paths,enabling global reconstruction of the attack scenario.Experimental results on both open-source and real-world datasets demonstrate that the proposed method effectively achieved attack scenario reconstruction while significantly reducing computational complexity compared to full analysis method,maintaining stable processing performance in incremental scenarios.

赵新建;汤慧敏;陈石;张玉健;张颂;程光

国网江苏省电力有限公司信息通信分公司,江苏 南京 210024东南大学网络空间安全学院,江苏 南京 211189国网江苏省电力有限公司信息通信分公司,江苏 南京 210024东南大学网络空间安全学院,江苏 南京 211189国网江苏省电力有限公司信息通信分公司,江苏 南京 210024东南大学网络空间安全学院,江苏 南京 211189

信息技术与安全科学

攻击场景重构多步攻击告警关联增量更新时间窗口

attack scenario reconstructionmulti-stage attackalert correlationincremental updatetime window

《网络与信息安全学报》 2026 (2)

143-155,13

国网江苏省电力有限公司科技项目(No.J2024086) The Science and Technology Project of State Grid JiangSu Electric Power Company(No.J2024086)

10.11959/j.issn.2096-109x.AQ25274

评论