Prediction method of 0day attack path based on cyber defense knowledge graph

To solve the difficulty of attack detection caused by the 0day vulnerability, a prediction method of 0day attack path based on cyber defense knowledge graph was proposed. The cyber defense knowledge graph was constructed to refine the discrete security data such as threat, vulnerability and asset in...

Full description

Bibliographic Details
Main Author: SUN Cheng, HU Hao, YANG Yingjie, ZHANG Hongqi
Format: Article
Language:English
Published: POSTS&TELECOM PRESS Co., LTD 2022-02-01
Series:网络与信息安全学报
Subjects:
Online Access:http://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2021101
_version_ 1818691382057893888
author SUN Cheng, HU Hao, YANG Yingjie, ZHANG Hongqi
author_facet SUN Cheng, HU Hao, YANG Yingjie, ZHANG Hongqi
author_sort SUN Cheng, HU Hao, YANG Yingjie, ZHANG Hongqi
collection DOAJ
description To solve the difficulty of attack detection caused by the 0day vulnerability, a prediction method of 0day attack path based on cyber defense knowledge graph was proposed. The cyber defense knowledge graph was constructed to refine the discrete security data such as threat, vulnerability and asset into the complete and high-related knowledge format by extracting concepts and entities related to network attack from cyber security ontology research finds and databases. Based on the knowledge integrated by the knowledge graph, assumed and restricted the unknown attributes such as the existence, availability and harmfulness of 0day vulnerabilities, and model the concept of "attack" as a relationship between attacker entities and device entities in the knowledge graph to transform the attack prediction to the link prediction of knowledge graph. According to this, apply path ranking algorithm was applied to mine the potential 0day attack in the target system and construct the 0day attack graph. Predicted the 0day attack path by utilizing the scores output by classifiers as the occurrence probabilities of single step attack and computing the occurrence probabilities of different attack paths. The experimental result shows that with the help of complete knowledge system provided by knowledge graph, the proposed method can reduce the dependence of prediction analysis on expert model and overcome the bad influence of 0day vulnerability to improve the accuracy of 0day attack prediction. And utilizing the characteristic that path ranking algorithm reasons based on the structure of graph can also help to backtrack the reasons of predicting results so as to improve the explainability of predicting.
first_indexed 2024-12-17T12:41:00Z
format Article
id doaj.art-db7f29d0b8944346886e86f3505c632c
institution Directory Open Access Journal
issn 2096-109X
language English
last_indexed 2024-12-17T12:41:00Z
publishDate 2022-02-01
publisher POSTS&TELECOM PRESS Co., LTD
record_format Article
series 网络与信息安全学报
spelling doaj.art-db7f29d0b8944346886e86f3505c632c2022-12-21T21:48:01ZengPOSTS&TELECOM PRESS Co., LTD网络与信息安全学报2096-109X2022-02-018115116610.11959/j.issn.2096−109x.2021101Prediction method of 0day attack path based on cyber defense knowledge graphSUN Cheng, HU Hao, YANG Yingjie, ZHANG Hongqi0 Information Engineering University, Zhengzhou 450001, ChinaTo solve the difficulty of attack detection caused by the 0day vulnerability, a prediction method of 0day attack path based on cyber defense knowledge graph was proposed. The cyber defense knowledge graph was constructed to refine the discrete security data such as threat, vulnerability and asset into the complete and high-related knowledge format by extracting concepts and entities related to network attack from cyber security ontology research finds and databases. Based on the knowledge integrated by the knowledge graph, assumed and restricted the unknown attributes such as the existence, availability and harmfulness of 0day vulnerabilities, and model the concept of "attack" as a relationship between attacker entities and device entities in the knowledge graph to transform the attack prediction to the link prediction of knowledge graph. According to this, apply path ranking algorithm was applied to mine the potential 0day attack in the target system and construct the 0day attack graph. Predicted the 0day attack path by utilizing the scores output by classifiers as the occurrence probabilities of single step attack and computing the occurrence probabilities of different attack paths. The experimental result shows that with the help of complete knowledge system provided by knowledge graph, the proposed method can reduce the dependence of prediction analysis on expert model and overcome the bad influence of 0day vulnerability to improve the accuracy of 0day attack prediction. And utilizing the characteristic that path ranking algorithm reasons based on the structure of graph can also help to backtrack the reasons of predicting results so as to improve the explainability of predicting.http://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2021101knowledge graph0day attackattack path prediction
spellingShingle SUN Cheng, HU Hao, YANG Yingjie, ZHANG Hongqi
Prediction method of 0day attack path based on cyber defense knowledge graph
网络与信息安全学报
knowledge graph
0day attack
attack path prediction
title Prediction method of 0day attack path based on cyber defense knowledge graph
title_full Prediction method of 0day attack path based on cyber defense knowledge graph
title_fullStr Prediction method of 0day attack path based on cyber defense knowledge graph
title_full_unstemmed Prediction method of 0day attack path based on cyber defense knowledge graph
title_short Prediction method of 0day attack path based on cyber defense knowledge graph
title_sort prediction method of 0day attack path based on cyber defense knowledge graph
topic knowledge graph
0day attack
attack path prediction
url http://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2021101
work_keys_str_mv AT sunchenghuhaoyangyingjiezhanghongqi predictionmethodof0dayattackpathbasedoncyberdefenseknowledgegraph