֪ʶµã£¬ÔõÑùÓ¦Óá°Ç徲֪ʶͼÆ×¡±Ê¶±ðÄÚ²¿Íþв£¿
2020-03-19
Ò»¡¢Åä¾°
ÄÚ²¿Íþв£¨Insider Threat£©ÊÇÖ¸ÄÚ²¿ÈËʹÓûñµÃµÄÐÅÍÐ×ö³ö¶ÔÊÚÐÅ×éÖ¯Õýµ±ÀûÒæ²»µÃµÄÐÐΪ£¬ÕâЩÀûÒæ°üÀ¨ÆóÒµµÄ¾¼ÃÀûÒæ¡¢ÓªÒµÔËÐС¢¶ÔÍâ·þÎñÒÔ¼°ÊÚÐÅÖ÷ÌåÉùÓþµÈ¡£ÄÚ²¿Íþв²»µ«½öÊÇ×éÖ¯Õýµ±³ÉÔ±µÄÓÐÒâ»òÎÞÒâµ¼ÖµÄ×éÖ¯ÀûÒæËðʧ£¬»¹°üÀ¨Ò»Ð©Íⲿαװ³ÉÄÚ²¿³ÉÔ±µÄ¹¥»÷¡£ÏÖÔÚÄÚÍøÍþв¼ì²â·ÖÎªÍøÂç²àÓëÖÕ¶Ë²à£¬ÍøÂç²à¼ì²éÖ÷ҪȫÁ÷Á¿£¬IPS/IDS, Öն˲àÖ÷ÒªÊÇEDR¡¢Ã۹޵ȣ¬ÉÐÓÐÏÖÔÚÊ¢ÐеÄUEBA£¬ÌìÌì»á±¬·¢´ó×ڵĸ澯ÐÅÏ¢£¬¶ø¹ØÓÚÇå¾²Ö°Ô±À´ËµÈ˹¤´¦Öóͷ£ÕâÖÖ¼¶±ðµÄ¸æ¾¯ÊDz»ÏÖʵµÄ£¬Í¨³£Ò»Ð©ÕæÊµµÄ¹¥»÷ÊÂÎñ»á±»ÑÍûÔڸ澯ÖС£ÔÚÒ»Ñùƽ³£ÔËάÖÐÍþвÆÀ¹À¾ÍÏÔµÃÓÈΪÖ÷Òª¡£
1¡¢Ç徲֪ʶͼÆ×
Ç徲֪ʶͼÆ×£¨Cyber Security Knowledge Graph£©ÊÇ֪ʶͼÆ×ÔÚÍøÂçÇå¾²ÁìÓòµÄÏÖʵӦÓ㬰üÀ¨»ùÓÚ±¾ÌåÂÛ¹¹½¨µÄÇ徲֪ʶ±¾Ìå¼Ü¹¹£¬ÒÔ¼°Í¨¹ýÍþв½¨Ä£µÈ·½·¨¶Ô¶àÔ´Òì¹¹µÄÍøÂçÇå¾²ÁìÓòÐÅÏ¢£¨ Heterogeneous Cyber Security Information£©¾ÙÐмӹ¤¡¢´¦Öóͷ£¡¢ÕûºÏ£¬×ª»¯³ÉΪµÄ½á¹¹»¯µÄÖÇ»ÛÇå¾²ÁìÓò֪ʶ¿â¡£¹ØÓÚÄÚÍøÊý¾ÝÀ´Ëµ£¬¸æ¾¯Êý¾ÝÓëÁ÷Á¿Êý¾ÝȱÉÙÏà¹ØµÄÓïÒ壬¶øÇ徲֪ʶͼÆ×ÈÚÈëÁËÒѾµÄÇ徲֪ʶ£¬ÄÜ´ó´óÌá¸ßÍþвʶ±ðÓëÆÀ¹ÀµÄ×¼±¸ÐÔ¡£
2¡¢Í¼Ç¶Èë
ͼǶÈ루Graph Embedding£¬Ò²½ÐNetwork Embedding£©ÊÇÒ»ÖÖ½«Í¼Êý¾Ý£¨Í¨³£Îª¸ßάŨÃܵľØÕó£©Ó³ÉäΪ±°Î¢Å¨ÃÜÏòÁ¿µÄÀú³Ì£¬Äܹ»ºÜºÃµØ½â¾öͼÊý¾ÝÄÑÒÔ¸ßЧÊäÈë»úеѧϰËã·¨µÄÎÊÌ⡣֪ʶͼÆ×ÊôÓÚÒ칹ͼÊý¾Ý£¬¼´½ÚµãÓë±ß²»Ö¹Ò»ÖÖÀàÐÍ¡£Ê¹ÓÃͼǶÈëÊÖÒÕ¿ÉÒÔ¸ßЧµÄʵÏÖ֪ʶͼÆ×ÆÊÎö¡£
¹Å°åµÄÍþвÆÀ¹ÀÒªÁ죬һÑùƽ³£Êǹ¥»÷Ä¿µÄ¹¹½¨ÏìÓ¦µÄ¹¥»÷ͼÀ´Á¿»¯£¬Ò»·½ÃæÕë¶Ô´ó¹æÄ£Êý¾Ý¹¹½¨¹¥»÷ͼµÄÖØ´óÐÔ½ÏÁ¿¸ß£¬Í¬Ê±¹¥»÷ͼ˼Á¿Î¬¶È½ÏÁ¿¾ÖÏÞ¡£Îª´ËÕë¶ÔÒѹ¹½¨µÄÇ徲֪ʶͼÆ×Ìá³öÒ»ÖÖ»ùÓÚͼǶÈëµÄÍþвÆÀ¹ÀÒªÁì¡£Ê×ÏÈÒÔÇ徲֪ʶͼÆ×ΪÊäÈ룬ʹÓÃͼÉñ¾ÍøÂ磨±àÂëÆ÷£©£¬¶ÔͼµÄ¼«µãÌìÉúǶÈëÏòÁ¿£¬ÆäÖÐÈÚÈëÁËÈ´¹¹ÍþвÆÀ¹À¼°ÊôÐÔÆÀ¹À¡£È»ºóʹÓÃͼÉñ¾ÍøÂçѧϰÿһ¸ö½Úµã¶Ôijһ¸ö½ÚµãµÄÍþв¶È£¬²¢¾ÛºÏ»ñµÃ¸Ã½ÚµãµÄÍþв¶È£¬ÔÙͨ¹ý½á¹¹ÍþвÆÀ¹À£¨ÖÐÐĶȣ©¾ÙÐе÷½â£¬ÔÆÔƵü´ú×îÖÕ»ñµÃͼÆ×ÖÐÿ¸ö½ÚµãµÄÍþв¶ÈÅÅÐò¡£
¶þ¡¢Ïà¹ØÊÖÒÕÏÈÈÝ
1¡¢ÖÇ»ÛÇ徲֪ʶͼÆ×
ÖÇ»ÛÇ徲֪ʶͼÆ×[9]£¨Intelligent Cyber Security Knowledge Graph£©ÊÇ֪ʶͼÆ×ÔÚÍøÂçÇå¾²ÁìÓòµÄÏÖʵӦÓ㬰üÀ¨»ùÓÚ±¾ÌåÂÛ¹¹½¨µÄÇ徲֪ʶ±¾Ìå¼Ü¹¹£¬ÒÔ¼°Í¨¹ýÍþв½¨Ä£µÈ·½·¨¶Ô¶àÔ´Òì¹¹µÄÍøÂçÇå¾²ÁìÓòÐÅÏ¢£¨Heterogeneous Cyber Security Information£©¾ÙÐмӹ¤¡¢´¦Öóͷ£¡¢ÕûºÏ£¬×ª»¯³ÉΪµÄ½á¹¹»¯µÄÖÇ»ÛÇå¾²ÁìÓò֪ʶ¿â¡£
Õë¶ÔÐÅÏ¢Çå¾²ÁìÓò֪ʶͼÆ×¹¹½¨µÄÁ½¸öÒªº¦ÒªËØ£¬¹¹½¨ÁËÍþвԪÓïÑÔÄ£×Ó¶ÔÍþв֪ʶµÄ½á¹¹»¯ÐÎò£¬°üÀ¨¿´·¨¡¢ÊµÌå¡¢ÊôÐԵĽç˵ÒÔ¼°ÖªÊ¶¹ØÏµµÄ½ç˵¡£Ñо¿ÖÐÒÀ¾ÝSTIX2.0ÒÔ¼°ÁìÓòר¼Ò֪ʶ£¬¹¹½¨Èý²ãÇ徲֪ʶͼÆ×£¬ÈçÏÂͼËùʾ¡£ÖªÊ¶Í¼Æ×¸¨ÖúÇå¾²ÊÂÎñÆÊÎö¡¢Çå¾²ºÏ¹æ±ê×¼¡¢APT×·×ÙËÝÔ´µÈÏÖʵӪҵ³¡¾°ËùÐèµÄÊý¾ÝÌåÏÖºÍÓïÒå¹ØÏµ¡£

ͼ2.1 Ç徲֪ʶͼÆ×
ÆäÖÐÐÅÏ¢²ãΪ֪ʶͼÆ×´ÓÍâ½ç³éÈ¡µÄ֪ʶʵÌ壬֪ʶ²ãºÍÖǻ۲ãΪÐÅÏ¢Çå¾²ÁìÓòÒªº¦¿´·¨¼°ÕâЩ¿´·¨Ö®¼äµÄÂß¼ÓïÒå¹ØÏµ¡£
ÔÚÍþвԪÓïÑÔÄ£×ÓÖУ¬ÍþвʵÌå¹¹½¨ºÍʵÌå¹ØÏµÊÇÁ½¸ö×îΪҪº¦Á½¸ö°ì·¨¡£
2¡¢Í¼Ç¶Èë
֪ʶͼÆ××î´óµÄÌØµãÊǾßÓÐÓïÒåÐÅÏ¢£¬È»¶ø¹¹½¨ºÃµÄÄÚÍøÇ徲֪ʶͼÆ×ÔõÑùÓ¦Óõ½ÄÚÍøÍþвʶ±ðÖС£Õâ¾ÍÐèҪһЩͼÆÊÎöÒªÁ죬¹Å°åµÄͼÆÊÎöÒªÁìÖ÷ÒªÊÇ£ºÂ·¾¶ÆÊÎö£¨¿É´ïÐÔ£¬×î¶Ì·¾¶£¬k-out£©£¬ÉçÇø·¢Ã÷µÈ¡£Ê¹ÓÃͼģ×Ó×öÄÚÍøÍþвʶ±ð£¬Ò»¸öºÜÖ±½ÓµÄÒªÁìÊÇʹÓÃÉçÇø·¢Ã÷[4,5,6]ÒªÁì¶ÔÍþвÖ÷Ìå¾ÙÐÐÉçÇø»®·Ö£¬°ÑÍþв¶È¸ßµÄ¹¥»÷Ö÷Ìå»®µ½Ò»Æð£¬´Ó¶øÊµÏÖÍþвʶ±ð¡£ÀíÂÛÉÏÕâÖÖÒªÁìÊÇ¿ÉÐеģ¬ÓÉÓÚ¹¹½¨µÄʵÌåÓëʵÌåÖ®¼äµÄ¹ØÁªºÍÐÐΪÔÚÉçÇøÄÚ¹ØÏµÏ¸ÃÜ£¬¶øÔÚÉçÇø¼ä¹ØÏµÏ£º±¡£
¶øÏÖÓÐÉçÇø·¢Ã÷ÒªÁìÒ»·½ÃæÖ»Ë¼Á¿¼«µãµÄÁÚÈ˹ØÁª£¬ºöÂÔÁËDZÔڵĽüÁÚ¹ØÏµ£¬Í¬Ê±£¬ÉçÇø·¢Ã÷µÄÖØÆ¯ºó½Ï¸ß£¬²»Êʺϴó¹æÄ£Í¼ÆÊÎö¡£
ΪÁ˶ÔÕâÖÖ¸ßάͼģ×Ó¾ÙÐнµÎ¬£¬Í¼Ç¶ÈëÊÖÒÕÓ¦Ô˶øÉú£¬Í¼Ç¶ÈëµÄʵÖÊÊÇÔÚÖ»¹Ü°ü¹Üͼģ×ÓµÄ½á¹¹ÌØÕ÷µÄÇéÐÎϰѸßάͼÊý¾ÝÓ³Éäµ½µÍάÏòÁ¿¿Õ¼ä¡£Éú³¤µ½ÏÖÔÚͼǶÈëÊÖÒÕÒѾ²»µ«½öÊÇÒ»ÖÖ½µÎ¬ÒªÁ죬ÓëÉî¶ÈѧϰÏàÍŽáºóͼǶÈëÊÖÒÕ¿ÉÒÔ¾ßÓиüÖØ´óµÄͼÅÌËãÓëͼÍÚ¾ò¹¦Ð§¡£

ͼ2.2 ͼǶÈëÁ÷³Ì
Ê×ÏÈͼ2.2£¨a£©ÖÐÊÇÓû§ÐÐΪ£¬´Ó֪ʶͼÆ×µÄ½Ç¶È¿ÉÒÔÁýͳ³Éͼ2.2£¨b£©ÖеÄͼģ×Ó¡£ÔÚÄ¿½ñÍÆ¼öϵͳºÍÇå¾²ÁìÓò¶¼½ÏÁ¿³£¼û£¬¶ø¹ØÓÚÁýͳµÄͼģ×ÓÔõÑùʹÓÃͼǶÈëÊÖÒÕ´¦Öóͷ£ÄØ£¿Ê×ÏÈ£¬DeepWalk[1,2,3]½«Ëæ»úÓÎ×ß»ñµÃµÄ½ÚµãÐòÁе±×ö¾ä×Ó£¬´Ó½Ø¶ÏµÄËæ»úÓÎ×ßÐòÁÐÖлñµÃÍøÂçµÄ²¿·ÖÐÅÏ¢£¬ÔÙ¾Óɲ¿·ÖÐÅÏ¢À´Ñ§Ï°½ÚµãµÄDZÔÚÌåÏÖ¡£¸ÃÒªÁì½èÖúÓïÑÔ½¨Ä£word2vecÖеÄÒ»¸öÄ£×Ó£¬Skip-gramÀ´Ñ§Ï°½ÚµãµÄÏòÁ¿ÌåÏÖ¡£½«ÍøÂçÖеĽڵãÄ£ÄâΪÓïÑÔÄ£×ÓÖеĵ¥´Ê£¬¶ø½ÚµãµÄÐòÁУ¨¿ÉÓÉËæ»úÓÎ×ß»ñµÃ£©Ä£ÄâΪÓïÑÔÖеľä×Ó£¬×÷ΪSkip-gramµÄÊäÈë¡£¿ÉÒÔ¿´³öÔÚÌåÏÖͼģ×ÓÖÐͼǶÈëÊÖÒÕÓÐ×ÔÈ»µÄÓÅÊÆ£¬ÓÉÓÚËü×Ô¼º°Ñ¶àάͼģ×ÓÓ³É䵽ͳһֱÁ¿¿Õ¼ä£¬¼«µãÖ®¼äµÄ¹ØÁª¹ØÏµ¿ÉÒÔͨ¹ý¼«µãÏòÁ¿µÄÏàËÆ¶ÈÅÌË㣬ÈÎÒ»¼«µãÓëÆäËû¼«µãµÄDZÔÚ¹ØÏµ¶¼¿ÉÒԺܿìµÄÅÌËã³öÀ´¡£
Ä¿½ñÒÑÓÐһЩÕë¶ÔÉçÇø·¢Ã÷µÄͼǶÈëÊÖÒÕ[6,7]¡£ÉçÇøÇ¶Èë¿ÉÒÔÐÎòÆä³ÉÔ±½ÚµãÔÚµÍά¿Õ¼äÖеÄÂþÑÜÇéÐΣ¬ÒÔÊÇÕâ´Î²»¿É¼òÆÓµÄ°ÑÉçÇø¿´³ÉÒ»¸öÏòÁ¿£¬¶øÊǵÍά¿Õ¼äÖеÄÂþÑÜ£¨¸ß˹»ìÏýÂþÑÜ£©¡£
Ò»·½Ã棬½ÚµãǶÈë¿ÉÒÔ×ÊÖúË¢ÐÂÉçÇø¼ì²â£¬´Ó¶øÊä³öÓÅÒìµÄÉçÇøÒÔ˳Ӧ¸üºÃµÄÉçÇøÇ¶È룬ÁíÒ»·½Ã棬ÉçÇøÇ¶Èë¿ÉÒÔͨ¹ýÒýÈëA Community-aware ¸ß½×½üËÆÐÔÀ´ÓÅ»¯½ÚµãǶÈë¡£ÔÚÕâÖ¸µ¼Ï£¬Ìá³öÁËÒ»¸öеÄÉçÇøÇ¶Èë¿ò¼Ü£¬Èçͼ2.3Ëùʾ¡£

ͼ2.3 ´óÁ÷Á¿¹¥»÷µÄ´ÎÊýת±ä
Èý¡¢»ùÓÚÇ徲֪ʶͼÆ×µÄÄÚÍøÍþвʶ±ð
»ùÓÚ֪ʶͼÆ×µÄÄÚÍøÍþвÖ÷Òª°üÀ¨Èý²¿·Ö£ºÍ¼Ä£×Ó¹¹½¨¡¢Í¼Ç¶ÈëºÍÍþвÆÀ¹À¡£Õë¶ÔÄÚÍøÍþвÒѾÓÐһЩ¼ì²â×é¼þ£¬¿ÉÊÇͨ³£ÕâЩ¼ì²â×°±¸Ö®¼äȱÉÙ¹ØÁªÐÔ£¬ÐèÒªÇå¾²Ö°Ô±×éºÏ²î±ð×é¼þµÄ¸æ¾¯Ê¹ÓÃÂÄÀúÆÊÎö£¬¶øÍ¼Ä£×Ó×Ô¼º¾ßÓкÜÇ¿µÄ¹ØÁªÐÔ£¬¿ÉÒÔÓÐÓùØÁª¶àÔ´Êý¾Ý£¬²¢ÇÒÒ×ÓÚÏÂ×ê¡£
1¡¢Í¼Ä£×Ó¹¹½¨
ͼģ×ӵĹ¹½¨Ö÷ÒªÊÇȷʵͼÖеÄʵÌåÓë¹ØÏµ£¬ÊµÌåµÄÑ¡Ôñͨ³£½ÏÁ¿ÈÝÒ×È·¶¨£¬Í¨³£ÒÔIP¡¢¶Ë¿Ú¡¢Íø¶Î¡¢¸æ¾¯¡¢Îļþ¡¢ÈÕÖ¾µÈʵÌåΪÖ÷£¬¶ø¹ØÏµÍ¨³£·ÖΪÏÔʾ¹ØÏµÓëÒþʽ¹ØÏµ£¬ÏÔʾ¹ØÏµÊÇÖ±½Ó¿ÉÒÔ»ñµÃµÄ¹ØÏµ£¬¶øÒþʽ¹ØÏµÊÇͨ¹ýÊý¾ÝÍÚ¾òÒªÁì»ñµÃµÄһЩÊý¾ÝÖаµº¬µÄ¹ØÁª¹ØÏµ¡£
£¨1£©ÊµÌå¹¹½¨
ʵÌåµÄ¹¹½¨Æ¾Ö¤³¡¾°µÄ²î±ð»áÓвî±ðÑ¡Ôñ£¬¿ÉÒÔ²ÎÕÕSTIX2.0ÖеÄÊ®¶þ¸ö¹¤¾ßÓòµÄ»®·Ö£¬ÒÔ¼°µ±ËÞÌìϹæÄ£ÄÚ¶ÔÇå¾²ÔªËØÐÎòµÄʹÓýÏΪÆÕ±éµÄ±ê×¼À´È·¶¨ÊµÌ壬±¾ÎÄÖ»ÏÈÈݼ¸¸ö½¹µãʵÌåÀàÐÍ£º
¹¥»÷ģʽ£º¹¥»÷ÌᳫÕßʹÓõÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò£¬²Î¿¼£ºÍ¨Óù¥»÷ģʽö¾ÙºÍ·ÖÀࣨCAPEC£©¡¢MITRE¹«Ë¾µÄPRE-ATT&CK¡¢ATT&CK¡¢Kill Chain
Ä¿µÄ¿ÍÌ壺¹¥»÷Ä¿µÄ×ʲú£¬²Î¿¼£ºÍ¨ÓÃÆ½Ì¨Ã¶¾Ù£¨CPE£©
ÍþвÖ÷Ì壺¹¥»÷ÌᳫÕߣ¬¿ÉÒÔÊÇСÎÒ˽¼Ò¡¢ÕûÌåºÍ×éÖ¯£¬²Î¿¼£ºÍþвÊðÀíΣº¦ÆÀ¹À£¨TARA£©ÖеÄÍþвÊðÀí¿â
Õ½Õù£ºÕë¶ÔÏêϸĿµÄµÄһϵÁжñÒâÐÐΪ»ò¹¥»÷
ÍþвָʾÆ÷£ºÔÚ¼ì²â»òȡ֤ÖУ¬¾ßÓиßÖÃÐŶȵÄÍþв¹¤¾ß»òÌØÕ÷ÐÅÏ¢¡£
ÄÚÍøÇéÐÎÖеÄÍþвÖ÷ÌåÊÇÖ¸¹¥»÷µÄÌᳫÕߣ¬Í¨³£Ö¸Á½À࣬һÀàÊÇ×éÖ¯ÄÚ²¿Ö°Ô±ÓÉÓÚСÎÒ˽¼ÒÔµ¹ÊÔÓÉÓÐÒâ»òÎÞÒâµÄÔì³ÉµÄÎ¥¹æÐÐΪ£»Ò»ÀàÊÇÍⲿÓû§Î±×°³ÉÄÚ²¿Óû§¾ÙÐÐһЩ¹¥»÷ÐÐΪ¡£Ä¿µÄ¿ÍÌåͨ³£Êǹ¥»÷µÄÄ¿µÄ£¬Í¨³£ÊÇÍø¶Î¡¢¶Ë¿Ú¡¢Öն˼°ÎļþµÈ¡£¹¥»÷ģʽ°üÀ¨ÒÑÓеÄһЩͨÓù¥»÷Õ½ÂÔÏà¹ØÖªÊ¶£¬ÈôÊǹ¥»÷Á´£¬att&ckµÈ£¬ÏÖÔÚһЩÍþв¼ì²â×é¼þ±¬·¢µÄ¸æ¾¯ÐÅÏ¢ÒѾ°üÀ¨Á˲¿·ÖÏà¹ØÖªÊ¶¡£
£¨2£©¹ØÏµ¹¹½¨
¹ØÏµµÄ¹¹½¨°üÀ¨Ö±½Ó¹ØÏµÓë¼ä½Ó¹ØÏµ¹¹½¨¡£Ö±½Ó¹ØÏµ½ÏÁ¿ÈÝÒ×»ñµÃ£¬ÄÚÍøÇéÐÎÖÐͨ³£ÄÜͨ¹ýÈÕÖ¾¡¢É³Ïä¡¢ÔʼÁ÷Á¿ºÍÍⲿÊý¾ÝÖ±½Ó»ñµÃµÄ¹ØÏµ¶Ô£¬ÀýÈ磬Îļþ»á¼ûÓòÃû£¬ÓòÃûÆÊÎöIP£¬Îļþ»á¼ûIPµÈ¡£
¼ä½Ó¹ØÏµÊÇͨ¹ý¼ä½Ó¹ØÁª»ñµÃµÄ¹ØÏµ£¬ºÃ±ÈʹÓÃͳһÖÖ¹¥»÷¹¤¾ßµÄ¹¥»÷ÕßÓÐÒ»¶¨µÄÏàËÆÐÔ£¬ÎļþÓëÎļþͨ¹ýÏàËÆ¶ÈÅÌËã»ñµÃµÄÏàËÆÐԵȵȶ¼ÊôÓÚ¼ä½Ó¹ØÏµ¡£ÕâÑùͨ¹ýÖ±½Ó¹ØÏµÓë¼ä½Ó¹ØÏµµÄ¹¹½¨¾Í×é³ÉÁËÄÚÍøÇ徲֪ʶͼÆ×¡£
2¡¢¶¯Ì¬ÍþвÆÀ¹À
ÔÚÄÚÍøÇéÐÎÖУ¬²î±ðµÄ¼ì²â×é¼þÌìÌì»á±¬·¢´ó×ÚµÄÍþв¸æ¾¯£¬¹ØÓÚÇå¾²Ö°Ô±À´ËµÈ˹¤´¦Öóͷ£Õâô´ó×ڵĸ澯ÊDz»ÏÖʵµÄ£¬¿ÉÊÇÕæÊµµÄ¸æ¾¯ÍùÍùÓֻᱻÕâЩ´ó×ÚµÄÎó±¨ËùÑÍû£¬ÓÐÓõÄÍþвÆÀ¹À¿ÉÄܸøÇå¾²Ö°Ô±Ìṩ´¦Öóͷ£ÍþвµÄÓÅÏÈ˳Ðò£¬´Ó´ó×ڵĸ澯ÖÐÑ¡Ôñ×îÓпÉÄܵĸ澯¡£ÏÖÔÚÍþвÆÀ¹ÀµÄÖ¸±ê½Ï¶à£¬²¢ÇÒʵÌåµÄÍþвˮƽÊÇËæ×Åʱ¼ä¶¯Ì¬×ª±äµÄ£¬ºÃ±Èij¸ö¹¥»÷Ô´·¢Ã÷ÁËÒ»¸ö¸ßΣÎó²îºó£¬Ëü×Ô¼ºµÄÍþв³ÌÐò¾Í±ä´ó¡£×¼È·µÄÍþвÆÀ¹ÀÊÇÄÚÍøÒ»Ñùƽ³£ÔËάËù¼±ÐèµÄ¡£
£¨1£©³õʼÍþв¶È
ÖÜÆÚÐÔ
ÖÜÆÚÐÔÖ¸±êÖ÷ÒªÓÃÀ´¶Ô¸æ¾¯Êý¾ÝµÄ±¬·¢Ôµ¹ÊÔÓɾÙÐÐÅжϣ¬Ò»Ñùƽ³£±»È䳿»òÕßľÂíѬȾµÄÖ÷ʱ»úÖÜÆÚÐԵط¢Ë͹¥»÷±¨ÎÄ£¬Æäÿ¸ôÒ»¶Îʱ¼ä·¢Ë͵Ĺ¥»÷±¨ÎÄÊýÄ¿ºÍÄÚÈÝÒ²¶¼ÏàËÆ£¬ÕâÑùµÄ¹¥»÷±¨ÎÄËäÈ»¶ÔÍøÂçÇå¾²Ò²×é³ÉÒ»¶¨µÄÍþв£¬µ«ÓÉÓÚÆä·¢Ëͱ¨ÎÄÊýĿһ¶¨¡¢ÄÚÈÝÏàËÆÒÔ¼°¾ßÓÐÖÜÆÚÐÔ·¢Ë͵ÄÌØµã£¬Ïà¹ØÓÚ¾ßÓÐÍ»·¢ÐÔ¡¢¹¥»÷ÊֶζàÑùÐÔµÄÈËΪµÄ×Ô¶¯¹¥»÷£¬¸üÈÝÒ×Ìá·À£¬ÆäÔì³ÉµÄÍþвҲÏà¶Ô½ÏµÍ¡£Îª´Ë£¬ÎÒÃÇÐèÒªÅжϸ澯ÐÅÏ¢ÊÇ·ñ¾ßÓÐÖÜÆÚÐÔ£¬²¢´ÓÖмõС¾ßÓÐÖÜÆÚÐÔľÂíµÈ¶ñÒâ´úÂ뱬·¢µÄ¸æ¾¯Íþв£¬Ìá¸ß¶ÔÍ»·¢ÊÂÎñÍþвÐÔµÄÅÌËã¡£
˼Á¿ÖÜÆÚÐÔÅÌËãµÄÅÓºéˮƽ£¬ÈôÊÇÒª¾ÙÐнÏΪ׼ȷµÄÖÜÆÚÐÔÅÌËã£¬ÆÆ·Ñʱ¼ä½Ï³¤£¬¶øÖÜÆÚÐÔÖ»ÊǶàÏîÖ¸±êÖеÄÒ»Ï¶øÈôÊÇÅÌËã̫Ϊ¼òÆÓ£¬ÓÖ²»¿É¹»ÌåÏÖ³öÖ¸±êµÄ×÷Óá£×ÛºÏ˼Á¿ÆäÅÌËãÁ¿ºÍÖ¸±êµÄ׼ȷ¶È£¬ÏÖ½«¹¥»÷ÖÜÆÚÐÔµÄÅÌËãÒªÁì½ç˵ÈçÏ¡£
¶Ô¹¥»÷Ô´µÄ²î±ðÀàÐ͵Ĺ¥»÷´ÎÊýÒÔСʱΪµ¥Î»¾ÙÐзÖʱ¼äµÄͳ¼Æ£¬¶ÔÿһÏîͳ¼ÆÖµ¾ÙÐз½²îÖµµÄÅÌË㣬ÈôÊÇ·½²îÖµ´óÓÚÉ趨ãÐÖµ£¬ÔòÒÔΪ¸ÃÀ๥»÷ÊֶεĹ¥»÷²»¾ßÓÐÖÜÆÚÐÔ£¬Ð¡ÓÚÉ趨ãÐÖµ£¬ÔòÒÔΪ¸ÃÀ๥»÷ÊÖ¶ÎʵÑéµÄ¹¥»÷¾ßÓÐÖÜÆÚÐÔ¡£
Îó²î
Ö÷Òª½ÓÄÉCVSS[8]ÆÀ¼Ûϵͳ£¨Common Vulnerability Scoring System£©ÖеÄTemporal Metrics×÷ΪÆÀ·Ö²Î¿¼£¬¸ÃÆÀ·ÖÄܹ»ÐÎò¹¥»÷ÕßʹÓøÃÎó²îºóÔì³ÉµÄÓ°ÏìˮƽºÍÄÑÒ×ˮƽ£¬Îó²îµÄTemporal ÆÀ·ÖÔ½´ó£¬ËµÃ÷ʹÓøÃÎó²î±¬·¢µÄÍþв¾ÍÔ½´ó£»TemporalÆÀ·ÖԽС£¬ËµÃ÷ʹÓøÃÎó²î±¬·¢µÄÍþв¾ÍԽС¡£ÖªÊ¶Í¼Æ×ʵÌåµÄÍþвֵµÄÅÌËãÒªÁìÈçϹ«Ê½Ëùʾ£¬ÆäÖÐaΪͼÖеĽڵ㣬TVL(a)´ú±í½ÚµãµÄÍþвֵ£¬Temporal Score(ra)´ú±ía¶ÔÓ¦µÄÎó²îµÄTemporalÆÀ·Ö¡£Ðж¯½ÚµãµÄÍþвֵ½ç˵ÈçÏ£º

Ä¿µÄ¿ÍÌåÖ÷ÒªÐÔ
Ä¿µÄ¿ÍÌåÓÉÓÚÆäÖ÷ÒªÐÔ²î±ð£¬±»¹¥»÷ºóÔì³ÉµÄΣº¦Ë®Æ½Ò²²î±ð¡£ÀýÈ磬һЩ²»Ö÷ÒªµÄFTP·þÎñÆ÷¡¢WEB·þÎñÆ÷»òÕßÃÛ¹Þ½Úµã¿ÉÄܱ»¸¶Óë1µÄÖ÷ÒªÐÔ£¬¶øÒ»Ð©Ö÷ÒªµÄÊý¾Ý´æ´¢·þÎñÆ÷ºÍ×ܿطþÎñÆ÷±»¸¶Óë9µÄÖ÷ÒªÐÔ£»ºÍCVSSµÄTemporalÆÀ·ÖÒ»Ñù£¬Ö÷»úµÄÖ÷ÒªÐÔ¿ÉÒÔÉèÖÃΪ0-10Çø¼äµÄ·ÖÊý¡£Ä¿µÄ¿ÍÌåµÄÍþвֵ½ç˵ÈçÏ£º

³öÓÚ¼ò»¯ÆÊÎö˼Á¿£¬Ôݶ¨Ã¿¸öÄ¿µÄ¿ÍÌåµÄÍþвֵ¶¼ÎªÏà¹ØÖ÷»úµÄÖ÷»úÖ÷ÒªÐÔµÄÆ½¾ùÖµ£¬²¢Î´Ë¼Á¿Ö÷»úÉϵÄϸ·ÖÓªÒµºÍÖ÷»ú²î±ðȨÏÞ¶ÔÍþвֵ±¬·¢µÄÓ°Ïì¡£Ö÷»úµÄÖ÷ÒªÐÔÔ½¸ß£¬¹¥»÷ÕßËù±¬·¢µÄÍþв¾ÍÔ½´ó¡£
£¨2£©ÍþвÆÀ¹À
¹ØÓÚÒÑÓеÄÕâЩÍþвÆÀ¹À£¬ÊÇ´Ó²î±ðά¶ÈÀ´½â¾öÍþвÆÀ¹ÀÎÊÌ⣬ÄÇô²î±ð½Ç¶ÈµÄÆÀ¹ÀÈçÔõÑùÈÚºÏÓÅ»¯³ÉΪÍþвÆÀ¹ÀµÄÎÊÌ⡣Ϊ´Ë£¬»ùÓÚÒѹ¹¹¹½¨µÄ֪ʶͼÆ×¾ÙÐÐÆÊÎö£¬Ê¹ÓÃͼǶÈë°Ñ²î±ðά¶ÈµÄÍþвÆÀ¹ÀÓ³É䵽ͳһ¿Õ¼äÖУ¬ÔÚ˼Á¿¸ü¶àÌØÕ÷¼°ÍþвµÄÓ°ÏìÇéÐÎÏ£¬ÔÚͳһ¿Õ¼ä¶Ô²î±ðʵÌå¾ÙÐÐÍþвÆÀ¹À£¬ÎÞÂÛÊÇЧÂʺ;«¶ÈÉ϶¼±È¹Å°åÒªÁìÓкܴóÌáÉý¡£

ͼ3.1 »ùÓÚ֪ʶͼÆ×µÄÍþвÆÀ¹À¿ò¼Ü
»ùÓÚͼǶÈëÊÖÒÕ£¬ÒѾ¿ÉÒÔÓÉ֪ʶͼÆ×ÕâÖÖÀëɢģ×Óת»»³ÉÌØÕ÷ÏòÁ¿ÕâÖÖÒ»Á¬ÌåÏÖ¡£È»ºó»ùÓÚͼµÄ½á¹¹ÌØÕ÷ºÍÏà¹ØÊôÐÔÌØÕ÷¾ÙÐÐÍþвÆÀ¹À£¬½á¹¹ÌØÕ÷ºÃ±ÈͼµÄÖÐÐÄÐÔ£¬ÓÉÓÚÔÚͼģ×ÓÖУ¬ÖÐÐĽڵãͨ³£ÌåÏÖͼµÄÖÐÐÄÌØÕ÷£¬ÖÐÐĽڵã¶ÔÆäËûËùÓнڵãµÄÓ°Ïì×î´ó£¬ÓÈÆäÊÇÔÚÍþвÈö²¥Àú³ÌÖеÄÓ°ÏìÒ²×î´ó¡£

ͼ3.2 ʹÓÃͼÉñ¾ÍøÂçÅÌËãÖ÷ÌåÍþвֵ
¹Å°åµÄÍþвÆÀ¹ÀÒªÁ죬һÑùƽ³£Êǹ¥»÷Ä¿µÄ¹¹½¨ÏìÓ¦µÄ¹¥»÷ͼÀ´Á¿»¯£¬Ò»·½ÃæÕë¶Ô´ó¹æÄ£Êý¾Ý¹¹½¨¹¥»÷ͼµÄÖØ´óÐÔ½ÏÁ¿¸ß£¬Í¬Ê±¹¥»÷ͼ˼Á¿Î¬¶È½ÏÁ¿¾ÖÏÞ¡£Îª´ËÕë¶ÔÒѹ¹½¨µÄÇ徲֪ʶͼÆ×Ìá³öÒ»ÖÖ»ùÓÚͼǶÈëµÄÍþвÆÀ¹ÀÒªÁì¡£Ê×ÏÈÒÔÇ徲֪ʶͼÆ×ΪÊäÈ룬ʹÓÃͼÉñ¾ÍøÂ磨±àÂëÆ÷£©£¬¶ÔͼµÄ¼«µãÌìÉúǶÈëÏòÁ¿£¬ÆäÖÐÈÚÈëÁËÈ´¹¹ÍþвÆÀ¹À¼°ÊôÐÔÆÀ¹À£¬È»ºóʹÓÃͼÉñ¾ÍøÂçѵÁ·Ã¿¸ö½Úµã¶Ôijһ½ÚµãµÄÍþв¶ÈȨֵ£¬¾ÓÉÒ»Ö±µÄµü´ú×îÖÕÌìÉú·µ»ØÖªÊ¶Í¼Æ×ÖнڵãµÄÍþв¶ÈÅÅÃû¡£
ÏÂÃæÏÈÈÝÆÀ¹ÀÄ£×ӵĽ¹µã£¬ÖªÊ¶Í¼Æ×ÖаüÀ¨¶àÖÖʵÌ壬ʵÌåÖеÄÖ±½ÓÓë¼ä½Ó¹ØÏµÌåÏÖ×ÅÍþвת´ï£¬ºÃ±È¹¥»÷ÕßÓµÓй¥»÷¹¤¾ß£¬ÄÇô¸ÃʵÌåµÄÍþв¶È¾Í»áÔöÌí£¬¹¥»÷Õß¾àÀëÄ¿µÄ×ʲúµÄ¾àÀë½ü£¬ÄÇô¸Ã¹¥»÷ÕßµÄÍþв¶È¾Í»áÔöÌíµÈµÈ£¬ÖÐÐĶÈÊÇָͼÖУ¬´¦Öóͷ£ÖÐÐĶÈÉϵĹ¥»÷ÕßµÄÍþв¶ÈÔ½´ó¡£ÔÚͼÉñ¾ÍøÂçÖÐÈÚºÏÒ»Ìø»ò¶àÌø½üËÆÑµÁ·ÖªÊ¶Í¼Æ×Öвî±ðµÄʵÌå¾ÛºÏµÄȨֵ£¬È»ºóÌìÉúеÄÍþвֵ£¬ÔÙʹÓÃÖÐÐĶȾÙÐе÷½â£¬½øÈëÏÂÒ»²ãѧϰ£¬Ö±µ½Öª×ãÖÕÖ¹Ìõ¼þ¡£
ËÄ¡¢×ܽá
ÏÖÔÚ£¬ÖªÊ¶Í¼Æ×ÔÚÍÆ¼ö£¬¼ìË÷ÁìÓòÒѾ»ñµÃÁËÆÕ±éÓ¦Ó㬵«ÔÚÇå¾²ÁìÓò֪ʶͼÆ×µÄÓ¦Óû¹´¦Öóͷ£Ì½Ë÷½×¶Î¡£¿ÉÊÇͼģ×ÓÒѾÔÚÇå¾²ÁìÓò¶à¸ö³¡¾°»ñµÃÓ¦Óò¢È¡µÃÁ˲»´íµÄЧ¹û£¬Ç徲֪ʶͼÆ×ÔÚÔÓеÄͼģ×ÓÖÐÈÚÈëÁ˸ü¶àµÄ֪ʶ£¬Îª¼ì²â¡¢ÆÊÎöÓëÏìÓ¦ÌṩÁ˸ü¶àµÄÓïÒåÐÅÏ¢¡£Î´À´ÖªÊ¶Í¼Æ×ÔÚÇå¾²ÁìÓò½«»áÓиü¶àµÄÓ¦Óá£
²Î¿¼ÎÄÏ×£º
[1].Perozzi B , Al-Rfou R , Skiena S . DeepWalk: Online Learning of Social Representations[J]. 2014.
[2].Jian T, Meng Q, Wang M, et al. LINE: Large-scale Information Network Embedding[C]// International Conference on World Wide Web. 2015.
[3]. Grover A , Leskovec J . node2vec: Scalable Feature Learning for Networks[J]. 2016.
[4].Newman M E J , Girvan M . Finding and Evaluating Community Structure in Networks[J]. Physical Review E, 2004, 69(2 Pt 2):026113.
[5].https://blog.csdn.net/ztf312/article/details/80680263.
[6]. Wang X , Cui P , Wang J , et al. Community Preserving Network Embedding[C]// The 31st AAAI Conference on Artificial Intelligence. 2017.
[7].Cavallari S , Zheng V W , Cai H , et al. Learning Community Embedding with Community Detection and Node Embedding on Graphs[C]// the 2017 ACM. ACM, 2017.
[8].Pengsu C, Lingyu W, Jajodia S, et al£®Aggregating CVSS Base Scores for Semantics-rich Network Security Metrics [A]£®// 2012 IEEE 31st Symposium on Reliable Distributed Systems (SRDS) [C], Irvine, CA: IEEE Press, 2012: 31-40£®
[9].»ùÓÚ֪ʶͼÆ×µÄAPT×é֯׷×ÙÖÎÀí,https://mp.weixin.qq.com/s/CluHeu1oy7DneBuR0cXZSQ

¾ÅÓÎÀϸçÔÆ







