《電子技術應用》
您所在的位置:首頁 > 通信与网络 > 设计应用 > 融合溯源图与知识图谱的APT攻击检测模型研究
融合溯源图与知识图谱的APT攻击检测模型研究
网络安全与数据治理
安渊1,鲍永庆2
1.国家计算机网络应急技术处理协调中心西藏分中心; 2.中共西藏自治区委员会网络安全和信息化委员会办公室
摘要: 针对高级持续性威胁(APT)攻击所具有的隐蔽性强、持续时间长、多阶段渐进的特点,提出了一种融合动态系统行为溯源图与静态威胁情报知识图谱的检测模型。该模型使用时空图注意力网络联合建模攻击链中的空间依赖与时间演化关系。通过图注意力网络捕捉实体间可疑关联,通过门控循环单元建模行为序列的阶段性演进,从而实现对APT攻击全链条的端到端检测。在WindowsAPTs Dataset 2025公开数据集上的实验表明,所提模型在APT多分类检测任务中性能良好,准确率达95.14%,F1分数为95.29%。
中圖分類號:TP393.08文獻標志碼:ADOI:10.19358/j.issn.2097-1788.2026.03.002
中文引用格式:安淵,鮑永慶. 融合溯源圖與知識圖譜的APT攻擊檢測模型研究[J].網絡安全與數據治理,2026,45(3):10-16.
英文引用格式:An Yuan,Bao Yongqing. Research on an APT attack detection model integrating provenance graphs and knowledge graphs[J].Cyber Security and Data Governance,2026,45(3):10-16.
Research on an APT attack detection model integrating provenance graphs and knowledge graphs
An Yuan1,Bao Yongqing2
1. National Computer Network Emergency Response Technical Team/Coordination Center of China, Xizang Branch;Office of the Cyberspace Administration and Informatization Committee of the Communist Party of China Xizang Autonomous Region Committee
Abstract: Advanced Persistent Threat (APT) attacks, characterized by strong concealment, long duration, and multistage progressive patterns, were addressed by a novel detection model. The model was constructed through the fusion of dynamic system behavior provenance graphs with static threat intelligence knowledge graphs. Spatial dependencies and temporal evolution relationships within attack chains were jointly modeled using spatialtemporal graph attention networks. Suspicious associations between entities were captured through graph attention mechanisms, while stagewise evolution of behavioral sequences was modeled using gated recurrent units, enabling endtoend detection of complete APT attack chains. Experiments on the public WindowsAPTs Dataset 2025 demonstrated that the proposed model performed well in the APT multiclassification detection task, with an accuracy of 95.14% and an F1score of 95.29%.
Key words : APT attack detection; provenance graph; knowledge graph

引言

高級持續性威脅(Advanced Persistent Threat,APT)攻擊因其隱蔽性、持續性和組織化特征,已經成為企業級網絡安全的核心挑戰。區別于傳統的網絡攻擊,APT攻擊通常由具備明確戰略意圖的組織發起,采用多階段、漸進式的攻擊模式,綜合運用社會工程學、零日漏洞利用及復雜的命令與控制網絡,旨在長期潛伏并竊取高價值信息[1]。傳統依賴已知特征碼匹配或基于單點異常閾值的檢測方法[2],因其缺乏對攻擊全局上下文和內在邏輯關聯的理解,往往難以奏效,導致漏報與誤報。

為突破這一瓶頸,基于系統審計日志構建數據溯源圖[3]的研究范式應運而生。該方法通過將分散的系統事件重構為具有因果與時間屬性的有向圖,能夠直觀地刻畫攻擊鏈中實體間的依賴關系,為還原復雜的多步攻擊提供了強大的結構化表示基礎。

與此同時,知識圖譜技術為整合與利用網絡安全領域的碎片化信息提供了理想框架。特別是以MITRE ATT&CK[4]為代表的知識庫,系統化地建模了APT組織、攻擊技術、利用工具及防御措施之間的復雜關聯。


本文詳細內容請下載:

http://m.tom3567.com/resource/share/2000007021


作者信息:

安淵1,鮑永慶2

(1.國家計算機網絡應急技術處理協調中心西藏分中心,西藏拉薩850000;

2.中共西藏自治區委員會網絡安全和信息化委員會辦公室,西藏拉薩850000)

2.jpg

此內容為AET網站原創,未經授權禁止轉載。
主站蜘蛛池模板: 亚洲精品在线视频观看| 亚洲一区精品电影| 91精品国产高清久久久久久91| 久久国产精品偷| 国产美女三级视频| 国产日韩在线亚洲字幕中文| 久久精品亚洲热| 日韩中文字幕第一页| 久青草国产97香蕉在线视频| 亚洲精品国产一区| 国产成人精品综合久久久| 国产精品一区二区三| 亚洲精品第一区二区三区| 国产精品久久久久久久久久久久| 日本午夜在线亚洲.国产| 欧美最猛黑人xxxx黑人猛叫黄| 91精品国产自产91精品| zzjj国产精品一区二区| 久久中文字幕国产| 美女久久久久久久久久久| 日韩视频 中文字幕| 国产精品美女诱惑| 日韩经典在线视频| 99精品欧美一区二区三区| 久久国产精品网站| 国产精品日韩在线| 国产不卡av在线免费观看| 久久精品国产欧美亚洲人人爽| 九九精品在线视频| 国产精品久久久久久久久久免费 | www婷婷av久久久影片| 一区二区在线中文字幕电影视频| 成人免费网站在线| 精品国模在线视频| 日韩视频在线一区| 国产精品流白浆视频| 久久久久亚洲精品国产| 日本亚洲精品在线观看| 欧美一区三区二区在线观看| 亚洲尤物视频网| 欧美国产激情视频|