Cyber-attack tracking method and device using behavior event-based relationship data collected from multiple domains, and storage medium storing instructions to perform cyber-attack tracking method
Proposed is a method for tracking a cyber-attack to be performed by a cyber-attack tracking device including a memory and a processor. The method may include determining a plurality of behavior events performed by network devices in one or more domains, and mapping the plurality of the behavior events onto metadata of preset standards. The method may also include generating relationship data indicating a relationship between behavior events mapped onto metadata designated as a preset group based on the metadata mapped onto the behavior events. The method may further include counting a number of behavior events related to a preset suspected behavior among behavior events having a relationship data same as a relationship data of a first behavior event to calculate score for the relationship data including the first behavior event.
1 . A method for tracking a cyber-attack to be performed by a cyber-attack tracking device including a memory and a processor, the method comprising:
determining a plurality of behavior events performed by network devices in one or more domains by:
determining original data for each behavior event that occurred in the network devices,
detecting a preset suspected attack behavior in the original data,
generating data related to the preset suspected attack behavior, and
generating behavior events comprising the data related to the preset suspected attack behavior, wherein the generating the data, the generating the behavior events, and the detecting the preset suspected attack behavior are performed by the processor to improve an efficiency of cyber-attack detection;
mapping the plurality of behavior events onto metadata of preset standards, wherein the metadata includes at least one of information classified as an event type, a process action, a file specification, a module characteristic, a network characteristic, or registry information for the plurality of behavior events, wherein mapping the plurality of behavior events onto metadata enables systematic identification and analysis of network activity;
generating relationship data indicating a relationship between behavior events mapped onto metadata designated as a preset group based on the metadata mapped onto the plurality of behavior events to systematically identify and analyze event paths from an initial stage of the cyber-attack to current behavior events to identify an intra-host attack behavior and an inter-host attack behavior of an attacker through the relationship data; and
counting a number of behavior events related to a preset suspected behavior among behavior events having the same relationship data as a first behavior event to calculate a score for the relationship data including the first behavior event to prioritize potential threats in real-time; and
providing a user terminal with the relationship data sorted in descending order of calculated scores and information on a domain, host, and behavior events included in the relationship data corresponding to a highest score, wherein a user of the user terminal is enabled to analyze the behavior events included in the provided relationship data to respond to cyber-attacks in advance and analyze causal relationships between behavior events to prevent advanced cyber-attacks,
wherein generating the relationship data includes generating inter-device relationship data indicating an inter-relationships between the plurality of behavior events occurred in network devices, and
wherein generating the inter-device relationship data includes generating the inter-device relationship data by grouping behavior events including a port of a transmission network device same as a port of a reception network device among behavior events having metadata related to a preset network characteristic for the plurality of the behavior events and including a file name of a transmitted file same as a file name of a received file or a hash value of the transmitted file same as a hash value of the received file.
2 . The method of claim 1 , wherein the metadata of the preset standards includes:
an event identification value specifying information on an event occurrence time, an event identification (ID), an event sequence, and an event group ID;
an event unique value specifying information on a file name and a file path; and
a suspected behavior value specifying information on attack tactics and attack techniques.
3 . The method of claim 1 , wherein generating the relationship data includes generating intra-device relationship data indicating an internal-relationship between the plurality of behavior events occurred in each network device.
4 . The method of claim 3 , wherein generating the intra-device relationship data includes generating the relationship data by grouping behavior events having metadata related to the same event group ID among behavior events having metadata related to a preset process action for the plurality of the behavior events.
5 . The method of claim 1 , wherein counting the number of behavior events related to the preset suspected behavior includes counting the number of duplicate behavior events as one when behavior events related to the preset suspected behavior occurs repeatedly among behavior events having the relationship data same as the first behavior event.
6 . A non-transitory computer readable storage medium storing computer executable instructions that cause, when executed by one or more processors, the one or more processors to perform the method of claim 1 .
7 . A cyber-attack tracking device comprising:
a memory configured to store one or more instructions; and
a processor configured to execute the one or more instructions to:
determine a plurality of behavior events performed by network devices in one or more domains by:
determining original data for each behavior event that occurred in the network devices,
detecting a preset suspected attack behavior in the original data,
generating data related to the preset suspected attack behavior, and
generating behavior events comprising the data related to the preset suspected attack behavior, wherein the generating the data, the generating the behavior events, and the detecting the preset suspected attack behavior are performed by the processor to improve an efficiency of cyber-attack detection;
map the plurality of the behavior events onto metadata of preset standards, wherein the metadata includes at least one of information classified as an event type, a process action, a file specification, a module characteristic, a network characteristic, or registry information for the plurality of behavior events, wherein mapping the plurality of behavior events onto metadata enables systematic identification and analysis of network activity;
generate relationship data indicating a relationship between behavior events mapped onto metadata designated as a preset group based on the metadata mapped onto the plurality of behavior events to systematically identify and analyze event paths from an initial stage of a cyber-attack to current behavior events to identify an intra-host attack behavior and an inter-host attack behavior of an attacker through the relationship data;
count a number of behavior events related to a preset suspected behavior among behavior events having the same relationship data as a first behavior event to calculate score for the relationship data including the first behavior event to prioritize potential threats in real-time; and
provide a user terminal with the relationship data sorted in descending order of calculated scores and information on a domain, host, and behavior events included in the relationship data corresponding to a highest score, wherein a user of the user terminal is enabled to analyze the behavior events included in the provided relationship data to respond to cyber-attacks in advance and analyze causal relationships between behavior events to prevent advanced cyber-attacks,
wherein to generate the relationship data, the processor is configured to generate inter-device relationship data indicating an inter-relationships between the plurality of behavior events occurred in network devices, and
wherein to generate the inter-device relationship data, the processor is configured to generate the inter-device relationship data by grouping behavior events including a port of a transmission network device same as a port of a reception network device among behavior events having metadata related to a preset network characteristic for the plurality of the behavior events and including a file name of a transmitted file same as a file name of a received file or a hash value of the transmitted file same as a hash value of the received file.
8 . The cyber-attack tracking device of claim 7 , wherein the metadata of the preset standards includes:
an event identification value specifying information on an event occurrence time, an event identification (ID), an event sequence, and an event group ID;
an event unique value specifying information on a file name and a file path; and
a suspected behavior value specifying information on attack tactics and attack techniques.
9 . The cyber-attack tracking device of claim 7 , wherein the processor is configured to generate intra-device relationship data indicating an internal-relationship between the plurality of behavior events occurred in each network device.
10 . The cyber-attack tracking device of claim 9 , wherein the processor is configured to generate the relationship data by grouping behavior events having metadata related to the same event group ID among behavior events having metadata related to a preset process action for the plurality of the behavior events.
11 . The cyber-attack tracking device of claim 7 , wherein the processor is configured to count the number of duplicate behavior events as one when behavior events related to the preset suspected behavior occurs repeatedly among behavior events having the relationship data same as the first behavior event.