融合溯源图与知识图谱的APT攻击检测模型研究
网络安全与数据治理
安渊1,鲍永庆2
1.国家计算机网络应急技术处理协调中心西藏分中心; 2.中共西藏自治区委员会网络安全和信息化委员会办公室
摘要: 针对高级持续性威胁(APT)攻击所具有的隐蔽性强、持续时间长、多阶段渐进的特点,提出了一种融合动态系统行为溯源图与静态威胁情报知识图谱的检测模型。该模型使用时空图注意力网络联合建模攻击链中的空间依赖与时间演化关系。通过图注意力网络捕捉实体间可疑关联,通过门控循环单元建模行为序列的阶段性演进,从而实现对APT攻击全链条的端到端检测。在WindowsAPTs Dataset 2025公开数据集上的实验表明,所提模型在APT多分类检测任务中性能良好,准确率达95.14%,F1分数为95.29%。
中圖分類號:TP393.08文獻標志碼:ADOI:10.19358/j.issn.2097-1788.2026.03.002
中文引用格式:安淵,鮑永慶. 融合溯源圖與知識圖譜的APT攻擊檢測模型研究[J].網絡安全與數據治理,2026,45(3):10-16.
英文引用格式:An Yuan,Bao Yongqing. Research on an APT attack detection model integrating provenance graphs and knowledge graphs[J].Cyber Security and Data Governance,2026,45(3):10-16.
中文引用格式:安淵,鮑永慶. 融合溯源圖與知識圖譜的APT攻擊檢測模型研究[J].網絡安全與數據治理,2026,45(3):10-16.
英文引用格式:An Yuan,Bao Yongqing. Research on an APT attack detection model integrating provenance graphs and knowledge graphs[J].Cyber Security and Data Governance,2026,45(3):10-16.
Research on an APT attack detection model integrating provenance graphs and knowledge graphs
An Yuan1,Bao Yongqing2
1. National Computer Network Emergency Response Technical Team/Coordination Center of China, Xizang Branch;Office of the Cyberspace Administration and Informatization Committee of the Communist Party of China Xizang Autonomous Region Committee
Abstract: Advanced Persistent Threat (APT) attacks, characterized by strong concealment, long duration, and multistage progressive patterns, were addressed by a novel detection model. The model was constructed through the fusion of dynamic system behavior provenance graphs with static threat intelligence knowledge graphs. Spatial dependencies and temporal evolution relationships within attack chains were jointly modeled using spatialtemporal graph attention networks. Suspicious associations between entities were captured through graph attention mechanisms, while stagewise evolution of behavioral sequences was modeled using gated recurrent units, enabling endtoend detection of complete APT attack chains. Experiments on the public WindowsAPTs Dataset 2025 demonstrated that the proposed model performed well in the APT multiclassification detection task, with an accuracy of 95.14% and an F1score of 95.29%.
Key words : APT attack detection; provenance graph; knowledge graph
引言
高級持續性威脅(Advanced Persistent Threat,APT)攻擊因其隱蔽性、持續性和組織化特征,已經成為企業級網絡安全的核心挑戰。區別于傳統的網絡攻擊,APT攻擊通常由具備明確戰略意圖的組織發起,采用多階段、漸進式的攻擊模式,綜合運用社會工程學、零日漏洞利用及復雜的命令與控制網絡,旨在長期潛伏并竊取高價值信息[1]。傳統依賴已知特征碼匹配或基于單點異常閾值的檢測方法[2],因其缺乏對攻擊全局上下文和內在邏輯關聯的理解,往往難以奏效,導致漏報與誤報。
為突破這一瓶頸,基于系統審計日志構建數據溯源圖[3]的研究范式應運而生。該方法通過將分散的系統事件重構為具有因果與時間屬性的有向圖,能夠直觀地刻畫攻擊鏈中實體間的依賴關系,為還原復雜的多步攻擊提供了強大的結構化表示基礎。
與此同時,知識圖譜技術為整合與利用網絡安全領域的碎片化信息提供了理想框架。特別是以MITRE ATT&CK[4]為代表的知識庫,系統化地建模了APT組織、攻擊技術、利用工具及防御措施之間的復雜關聯。
本文詳細內容請下載:
http://www.tom3567.com/resource/share/2000007021
作者信息:
安淵1,鮑永慶2
(1.國家計算機網絡應急技術處理協調中心西藏分中心,西藏拉薩850000;
2.中共西藏自治區委員會網絡安全和信息化委員會辦公室,西藏拉薩850000)

此內容為AET網站原創,未經授權禁止轉載。
