物联网(Internet of Things,IoT)技术的快速发展带来了巨大的市场潜力,同时也带来了安全和隐私问题。传统的安全方法已不能应对新的网络威胁,威胁情报和安全态势感知等主动防御策略应运而生。知识图谱技术为解决威胁情报的提取、整合和...物联网(Internet of Things,IoT)技术的快速发展带来了巨大的市场潜力,同时也带来了安全和隐私问题。传统的安全方法已不能应对新的网络威胁,威胁情报和安全态势感知等主动防御策略应运而生。知识图谱技术为解决威胁情报的提取、整合和分析提供了新的思路。首先回顾了物联网安全本体的构建,包括通用安全本体和特定领域安全本体。接着,梳理了威胁情报信息抽取的关键技术,包括基于规则匹配、统计学习和深度学习的方法。然后,探讨了物联网威胁情报知识图谱的构建框架,涉及数据源、信息抽取、本体构建等方面。最后,讨论了物联网威胁情报知识图谱的应用情景,并指出当前研究面临的挑战,展望了未来的研究方向。展开更多
In the tobacco industry,insider employee attack is a thorny problem that is difficult to detect.To solve this issue,this paper proposes an insider threat detection method based on heterogeneous graph embedding.First,t...In the tobacco industry,insider employee attack is a thorny problem that is difficult to detect.To solve this issue,this paper proposes an insider threat detection method based on heterogeneous graph embedding.First,the interrelationships between logs are fully considered,and log entries are converted into heterogeneous graphs based on these relationships.Second,the heterogeneous graph embedding is adopted and each log entry is represented as a low-dimensional feature vector.Then,normal logs and malicious logs are classified into different clusters by clustering algorithm to identify malicious logs.Finally,the effectiveness and superiority of the method is verified through experiments on the CERT dataset.The experimental results show that this method has better performance compared to some baseline methods.展开更多
为解决电力监控系统现有安全策略面对新型攻击防护能力不足的问题,文中提出一种基于对抗战术、技术和通用知识(adversarial tactics,techniques,and common knowledge,ATT&CK)框架的威胁路径构自动建方法。该方法首先基于设备间的...为解决电力监控系统现有安全策略面对新型攻击防护能力不足的问题,文中提出一种基于对抗战术、技术和通用知识(adversarial tactics,techniques,and common knowledge,ATT&CK)框架的威胁路径构自动建方法。该方法首先基于设备间的连通状况构建网络无向图;然后依据资产分级信息构建威胁移动路径;最后依据资产分类信息、ATT&CK框架以及网络杀伤链,补全威胁移动路径信息,完成威胁路径构建。该方法不仅为电力系统安全策略的制定提供了理论依据和支持,还为检测到威胁时自适应调整网络安全策略提供了可能。展开更多
文摘物联网(Internet of Things,IoT)技术的快速发展带来了巨大的市场潜力,同时也带来了安全和隐私问题。传统的安全方法已不能应对新的网络威胁,威胁情报和安全态势感知等主动防御策略应运而生。知识图谱技术为解决威胁情报的提取、整合和分析提供了新的思路。首先回顾了物联网安全本体的构建,包括通用安全本体和特定领域安全本体。接着,梳理了威胁情报信息抽取的关键技术,包括基于规则匹配、统计学习和深度学习的方法。然后,探讨了物联网威胁情报知识图谱的构建框架,涉及数据源、信息抽取、本体构建等方面。最后,讨论了物联网威胁情报知识图谱的应用情景,并指出当前研究面临的挑战,展望了未来的研究方向。
基金Supported by the National Natural Science Foundation of China(No.62203390)the Science and Technology Project of China TobaccoZhejiang Industrial Co.,Ltd(No.ZJZY2022E004)。
文摘In the tobacco industry,insider employee attack is a thorny problem that is difficult to detect.To solve this issue,this paper proposes an insider threat detection method based on heterogeneous graph embedding.First,the interrelationships between logs are fully considered,and log entries are converted into heterogeneous graphs based on these relationships.Second,the heterogeneous graph embedding is adopted and each log entry is represented as a low-dimensional feature vector.Then,normal logs and malicious logs are classified into different clusters by clustering algorithm to identify malicious logs.Finally,the effectiveness and superiority of the method is verified through experiments on the CERT dataset.The experimental results show that this method has better performance compared to some baseline methods.
文摘为解决电力监控系统现有安全策略面对新型攻击防护能力不足的问题,文中提出一种基于对抗战术、技术和通用知识(adversarial tactics,techniques,and common knowledge,ATT&CK)框架的威胁路径构自动建方法。该方法首先基于设备间的连通状况构建网络无向图;然后依据资产分级信息构建威胁移动路径;最后依据资产分类信息、ATT&CK框架以及网络杀伤链,补全威胁移动路径信息,完成威胁路径构建。该方法不仅为电力系统安全策略的制定提供了理论依据和支持,还为检测到威胁时自适应调整网络安全策略提供了可能。