基于事件语义关联融合的APT攻击场景重构方法
电子技术应用
乌吉斯古愣,汪枫云,陈静,王玥
中国电子科技集团公司第十五研究所
摘要: 高级持续性威胁(APT)攻击具有高度隐蔽性、长期性和阶段性,对关键信息基础设施构成严重威胁,其攻击场景构成典型的复杂攻击场景。传统基于单点的检测方法难以从海量异构的事件日志集中有效还原此类攻击的全貌。提出一种基于事件语义关联融合的APT攻击场景重构方法。首先,设计了一个集成大语言模型(LLM)能力的多层次、语义增强型事件日志关联框架,通过引入安全实体和攻击行为语义,构建了从“攻击短链”到“攻击长链”的关联结构。其次,针对攻击行为与攻击阶段映射的不确定性问题,构建了一个隐马尔科夫模型的攻击阶段推理模型,结合事件语义信息,将攻击长链映射到标准杀伤链阶段,从而识别出完整的APT攻击链。实验结果表明,该方法在包含噪声和APT攻击的模拟数据集合中,能够有效识别完整及部分观测缺失的APT攻击场景,显著提升了场景重构的准确性和鲁棒性。
中圖分類號:TP393 文獻標志碼:A DOI: 10.16157/j.issn.0258-7998.267942
中文引用格式: 烏吉斯古愣,汪楓云,陳靜,等. 基于事件語義關聯融合的APT攻擊場景重構方法[J]. 電子技術應用,2026,52(7):68-76.
英文引用格式: Wujisiguleng ,Wang Fengyun,Chen Jing,et al. APT attack scenario reconstruction via fusing event semantic correlations[J]. Application of Electronic Technique,2026,52(7):68-76.
中文引用格式: 烏吉斯古愣,汪楓云,陳靜,等. 基于事件語義關聯融合的APT攻擊場景重構方法[J]. 電子技術應用,2026,52(7):68-76.
英文引用格式: Wujisiguleng ,Wang Fengyun,Chen Jing,et al. APT attack scenario reconstruction via fusing event semantic correlations[J]. Application of Electronic Technique,2026,52(7):68-76.
APT attack scenario reconstruction via fusing event semantic correlations
Wujisiguleng ,Wang Fengyun,Chen Jing,Wang Yue
The 15th Research Institute of China Electronics Techology Group Corporation
Abstract: Advanced Persistent Threat (APT) attacks pose severe risks to critical information infrastructure due to their high degree of stealth, persistence, and phased progression. The attack scenarios of APT constitute typical complex attack patterns. Traditional point-based detection methods struggle to effectively reconstruct the complete picture of such attacks from massive and heterogeneous event log sets. This paper proposes an APT attack scenario reconstruction method based on the fusion of event semantic correlations. First, a multi-level, semantic-enhanced event log correlation framework integrated with Large Language Model (LLM) capabilities is designed, by incorporating security entity and attack behavior semantics, it constructs a correlation structure from "attack short chains" to "attack long chains". Second, to address the uncertainty in mapping attack behaviors to attack phases, a Hidden Markov Model (HMM)-based attack phase inference model is constructed. By integrating event semantic information, this model maps attack long chains to standard kill chain phases, thereby identifying complete APT attack chains. Experimental results demonstrate that, on a simulated dataset containing noise and APT attacks, the proposed method can effectively identify complete and partially observed APT attack scenarios, significantly improving the accuracy and robustness of scenario reconstruction.
Key words : Advanced Persistent Threat (APT);Large Language Model (LLM);semantic correlation fusion;Hidden Markov Model (HMM);attack scenario reconstruction
引言
隨著網絡空間對抗的日益加劇,高級持續性威脅(Advanced Persistent Threat, APT)已成為國家關鍵信息基礎設施和重要企業面臨的最嚴峻安全挑戰之一。APT攻擊通常由具備強大資源和明確目標的攻擊者發起,其攻擊過程具有精心策劃、長期潛伏、多階段遞進、手段復雜多變等特征。此類攻擊形成的攻擊場景是一種典型的復雜攻擊場景,它由一系列在時間上可能跨度極大、在空間上分散于不同網絡節點、在邏輯上緊密關聯的惡意事件構成。
面對APT威脅,傳統的基于特征碼匹配或單點異常檢測的方法,主要關注提高檢測告警而非感知發現APT攻擊過程,因為他們只關注孤立的攻擊瞬間,而無法從海量、混雜的安全事件中識別出跨域、跨時的內在關聯性。因此,對復雜攻擊場景進行精準還原,即從底層觀測數據中重建攻擊者的完整行動鏈條,對于理解攻擊意圖、評估損害范圍、實施精準溯源和定制有效防御策略具有至關重要的意義。
本文旨在提出一種系統化的復雜攻擊場景重構方法。核心思路是:首先對多源異構的事件日志進行關聯分析,初步構建出攻擊片段(攻擊短鏈);然后通過進一步關聯融合這些攻擊片段,形成描述整個攻擊活動的長鏈;最后,利用隱馬爾科夫模型(Hidden Markov Model, HMM)對攻擊長鏈事件序列進行抽象和推理,將其映射到“殺傷鏈”等高層攻擊模型階段,從而實現對攻擊者行為邏輯和攻擊進展的深層理解。
本文詳細內容請下載:
http://www.tom3567.com/resource/share/2000007143
作者信息:
烏吉斯古愣,汪楓云,陳靜,王玥
(中國電子科技集團公司第十五研究所,北京 100083)

此內容為AET網站原創,未經授權禁止轉載。
