[1]陈玉杰,陈俊丽,张汉举.基于ATT&CK框架的攻击检测系统设计[J].计算机技术与发展,2025,(10):89-97.[doi:10.20165/j.cnki.ISSN1673-629X.2025.0148]
CHEN Yu-jie,CHEN Jun-li,ZHANG Han-ju.Design of Attack Detection System Based on ATT&CK Framework[J].,2025,(10):89-97.[doi:10.20165/j.cnki.ISSN1673-629X.2025.0148]
点击复制
基于ATT&CK框架的攻击检测系统设计(
)
《计算机技术与发展》[ISSN:1006-6977/CN:61-1281/TN]
- 卷:
-
- 期数:
-
2025年10期
- 页码:
-
89-97
- 栏目:
-
网络空间安全
- 出版日期:
-
2025-10-10
文章信息/Info
- Title:
-
Design of Attack Detection System Based on ATT&CK Framework
- 文章编号:
-
1673-629X(2025)10-0089-09
- 作者:
-
陈玉杰1; 陈俊丽1; 张汉举2
-
1. 上海大学 通信与信息工程学院,上海 200444;
2. 上海博弋信息科技有限公司,上海 200030
- Author(s):
-
CHEN Yu-jie1; CHEN Jun-li1; ZHANG Han-ju2
-
1. School of Communication and Information Engineering,Shanghai University,Shanghai 200444,China;
2. Shanghai Boyi Information Technology Co.,Ltd.,Shanghai 200030,China
-
- 关键词:
-
ATT& CK框架; 攻击检测; 技战术知识库; 检测规则; 攻击链路
- Keywords:
-
ATT& CK framework; attack detection; technical and tactical knowledge base; detection rules; attack link
- 分类号:
-
TP39
- DOI:
-
10.20165/j.cnki.ISSN1673-629X.2025.0148
- 摘要:
-
随着计算机技术的蓬勃发展和网络攻击手段的日益繁杂,网络安全防护面临着严峻挑战。针对企事业单位对于网络攻击的检测维度单一、范围狭隘以及无法及时察觉到攻击者的潜伏驻留点和快速溯源这一现状,该文设计了基于ATT&CK框架的攻击检测系统,为企事业单位打造一道坚固的网络安全防线。该系统深度挖掘ATT&CK框架所蕴含的丰富技战术知识库资源,通过自然语言处理技术提取攻击技术描述中具有关键指示意义的动名词组合,为构建精准且全面的检测规则提供核心依据,实现对于网络攻击的全面检测。基于检测到的攻击行为,对攻击行为进行特征提取,获取其中的时间戳、来源IP、目标IP等信息,根据提取到的信息利用K-means聚类算法实现对攻击行为的智能分类和有序组织。以时间序列为脉络,深度梳理攻击行为的先后逻辑关系,构建完整且有序的攻击链路,从而实现快速定位到攻击者当前的驻留点以及攻击发生过后的快速溯源,有力保障企事业单位网络环境的安全稳定。
- Abstract:
-
With the vigorous development of computer technology and the increasing complexity of network attack methods,network security protection is facing severe challenges. We design an attack detection system based on the ATT&CK framework to address the current situation where enterprises and institutions have a single dimension,narrow scope,and cannot detect attackers’ hidden residence points and quickly trace their origins in a timely manner for detecting network attacks. The system aims to create a solid network security defense line for enterprises and institutions. The system deeply explores the rich technical and tactical knowledge base resources contained in the ATT&CK framework,extracts key indicative noun combinations from attack technology descriptions through natural language processing technology,and provides core basis for constructing accurate and comprehensive detection rules,achieving comprehensive detection of network attacks. Based on the detected attack behavior,feature extraction is carried out to obtain information such as timestamp,source IP,target IP,etc. According to the extracted information,K-means clustering algorithm is used to achieve intelligent classification and orderly organization of attack behavior. Using time series as the context,the sequential logical relationship of attack behavior is deeply sorted out,and a complete and orderly attack chain is constructed to quickly locate the attacker’s current residence point and quickly trace the source of the attack after it occurs,effectively ensuring the security and stability of the network environment of enter-prises and institution.
更新日期/Last Update:
2025-10-10