亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

CSKG4APT: A Cybersecurity Knowledge Graph for Advanced Persistent Threat Organization Attribution

计算机科学 计算机安全 归属 网络攻击 本体论 心理学 社会心理学 认识论 哲学
作者
Yitong Ren,Yanjun Xiao,Yinghai Zhou,Zhiyong Zhang,Zhihong Tian
出处
期刊:IEEE Transactions on Knowledge and Data Engineering [IEEE Computer Society]
卷期号:35 (6): 5695-5709 被引量:187
标识
DOI:10.1109/tkde.2022.3175719
摘要

Open-source cyber threat intelligence (OSCTI) is becoming more influential in obtaining current network security information. Most studies on cyber threat intelligence (CTI) focus on automating the extraction of threat entities from public sources that describe attack events. The cybersecurity knowledge graph aims to change the expression of threat knowledge so that security researchers can accurately and efficiently obtain various types of threat information for preliminary intelligent decisions. The attribution technology can not only assist security analysts in detecting advanced persistent threats, but can also identify the same threat from different attack events. Therefore, it is important to trace the attack threat actor. In this study, we used the knowledge graph technology, considered the latest research on cyber threat attack attribution, and thoroughly examined key related technologies and theories in the process of constructing and applying the advanced persistent threat (APT) knowledge graph from OSCTI. We designed a cybersecurity platform named CSKG4APT based on a knowledge graph. Inspired by the theory of ontology, we constructed CSKG4APT as an APT knowledge graph model based on real APT attack scenarios. We then designed an APT threat knowledge extraction algorithm for completing and updating the knowledge graph using deep learning and expert knowledge. Finally, we proposed a practical APT attack attribution method with attribution and countermeasures. CSKG4APT is not a passive defense method in traditional network confrontation but one that integrates a large amount of fragmented intelligence and can actively adjust its defense strategy. It lays the foundation for further dominance in network attack and defense.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
6秒前
wanci应助celine采纳,获得10
7秒前
科目三应助juaner采纳,获得10
11秒前
cc发布了新的文献求助20
22秒前
25秒前
小透明发布了新的文献求助10
32秒前
Copyright应助科研通管家采纳,获得20
50秒前
丘比特应助勤恳的背包采纳,获得10
1分钟前
1分钟前
1分钟前
尼龙niuniu发布了新的文献求助10
1分钟前
1分钟前
juaner发布了新的文献求助10
1分钟前
1分钟前
1分钟前
celine发布了新的文献求助10
1分钟前
小二郎应助尼龙niuniu采纳,获得10
1分钟前
juaner完成签到,获得积分10
1分钟前
2分钟前
2分钟前
2分钟前
2分钟前
2分钟前
共享精神应助勤恳的背包采纳,获得10
3分钟前
3分钟前
尼龙niuniu发布了新的文献求助10
3分钟前
terryok完成签到,获得积分10
3分钟前
非洲大象完成签到,获得积分10
3分钟前
所所应助优秀的夏兰采纳,获得10
3分钟前
Jasper应助尼龙niuniu采纳,获得10
3分钟前
Suzanne完成签到,获得积分10
4分钟前
4分钟前
柳贯一发布了新的文献求助10
4分钟前
内啡肽完成签到 ,获得积分10
4分钟前
CMUSK完成签到,获得积分10
4分钟前
4分钟前
5分钟前
噗愣噗愣地刚发芽完成签到 ,获得积分10
5分钟前
5分钟前
minnie完成签到 ,获得积分10
5分钟前
高分求助中
GL 2 A method for assessing the in-place cleanability of food processing equipment, Fourth Edition, December 2023 3000
Annie Ernaux: De la perte au corps glorieux 600
Writing Systems 500
Understanding Modeling and Simulation of Polymerization Reactions 400
Invited Discussant 63O and 64O 400
A revision of Limenitis helmanni and its related species (Nymphalidae) from Central and South China 400
Direct and Iterative Linear System Solvers 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6826864
求助须知:如何正确求助?哪些是违规求助? 8538869
关于积分的说明 18170992
捐赠科研通 6165025
什么是DOI,文献DOI怎么找? 3035384
关于科研通互助平台的介绍 2017634
邀请新用户注册赠送积分活动 2012254