融合溯源图与知识图谱的APT攻击检测模型研究OA
Research on an APT attack detection model integrating provenance graphs and knowledge graphs
针对高级持续性威胁(APT)攻击所具有的隐蔽性强、持续时间长、多阶段渐进的特点,提出了一种融合动态系统行为溯源图与静态威胁情报知识图谱的检测模型.该模型使用时空图注意力网络联合建模攻击链中的空间依赖与时间演化关系.通过图注意力网络捕捉实体间可疑关联,通过门控循环单元建模行为序列的阶段性演进,从而实现对APT攻击全链条的端到端检测.在Windows-APTs Dataset 2025 公开数据集上的实验表明,所提模型在APT多分类检测任务中性能良好,准确率达95.14%,F1 分数为95.29%.
Advanced Persistent Threat(APT)attacks,characterized by strong concealment,long duration,and multistage progressive pat-terns,were addressed by a novel detection model.The model was constructed through the fusion of dynamic system behavior provenance graphs with static threat intelligence knowledge graphs.Spatial dependencies and temporal evolution relationships within attack chains were jointly modeled using spatial-temporal graph attention networks.Suspicious associations between entities were captured through graph attention mecha-nisms,while stage-wise evolution of behavioral sequences was modeled using gated recurrent units,enabling end-to-end detection of complete APT attack chains.Experiments on the public Windows-APTs Dataset 2025 demonstrated that the proposed model performed well in the APT multi-classification detection task,with an accuracy of 95.14%and an F1-score of 95.29%.
安渊;鲍永庆
国家计算机网络应急技术处理协调中心西藏分中心,西藏 拉萨 850000中共西藏自治区委员会网络安全和信息化委员会办公室,西藏 拉萨 850000
信息技术与安全科学
APT攻击检测溯源图知识图谱
APT attack detectionprovenance graphknowledge graph
《网络安全与数据治理》 2026 (3)
10-16,7
评论