谭彬, 梁业裕, 李伟渊. Traffic based attack traceability analysis and protection method research[J]. 2019, 32(12): 57-64. DOI: 10.13992/j.cnki.tetas.2019.12.011.
基于流量的攻击溯源分析和防护方法研究
摘要
针对近年来境外黑客、APT组织、恶意软件攻击和僵尸网络活动愈发频繁的情况
本文进行了基于流量的攻击溯源技术研究、开发、部署与应用
系统融合了传统的基于规则的检测技术、机器学习和其它高级分析技术
通过监控网络流量、连接和对象
找出恶意的行为迹象
尤其是失陷后的痕迹。同时构建基于知识图谱的统一情报元语描述模型、基于知识图谱和攻击链的关联推理模型
通过分析公网全量设备流量
发现攻击信息
并通过智能关联分析引擎实现攻击链确认
实现有效攻击行为的精准检测
利用黑洞路由进行链路一键处置
实现对攻击行为的快速处置。
Abstract
In view of the increasing frequency of overseas hackers
APT organizations
malware attacks and botnet activities in recent years
this article has carried out the research
development
deployment and application of traffic based attack traceability technology. The system integrates the traditional rule-based detection technology
machine learning and other advanced analysis technologies
and finds out the evil through monitoring network traffic
connections and objects signs of intentional behavior
especially after the fall. At the same time
the unified information meta language description model based on knowledge map and the association reasoning model based on knowledge map and attack chain are constructed. By analyzing the total device traffic of public network
the attack information is found
and the attack chain confirmation is realized through the intelligent association analysis engine
so as to realize the accurate detection of effective attack behavior. The black hole route is used for the link key disposal
so as to realize the attack behavior rapid disposal.