预训练模型与因果挖掘结合的多步攻击检测
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

国家自然科学基金 (62102449)


Multi-step Attack Detection Combining Pre-trained Model with Causal Mining
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    针对复杂多步攻击发现中告警多源异构、表述不统一及告警间因果关系难以准确识别的问题, 提出了一种预训练模型与因果挖掘相结合的多步攻击检测方法. 首先, 利用经过SimCSE优化后的BERT模型对告警文本进行语义向量提取并进行相似性计算, 实现告警表述统一化处理, 降低告警冗余. 其次, 依据时间邻近性、地址相关性与严重性递增等关联规则构建初始因果关系图. 进一步结合时间感知图注意力网络与NOTEARS因果结构学习方法, 以修正告警节点间的因果关系, 从而剔除虚假关联边, 识别完整的复杂多步攻击. 实验结果表明, 所提方法能够有效提升对复杂多步攻击的检测准确率.

    Abstract:

    To address the problems of multi-source heterogeneous alerts, inconsistent alert descriptions, and difficulties in identifying causal relationships between alerts in complex multi-step attack detection, this study proposes a detection method that combines pre-trained models with causal mining. First, a BERT model optimized with SimCSE is used to extract semantic vectors from alert texts and compute their similarity. This achieves unified alert representation and reduces alert redundancy. Second, an initial causal graph is constructed based on association rules, including temporal proximity, address correlation, and severity escalation. A time-aware graph attention network is then combined with the NOTEARS causal structure learning method to refine causal relationships among alert nodes. This eliminates false correlation edges and identifies complete complex multi-step attacks. Experimental results show that the proposed method effectively improves the detection accuracy of complex multi-step attacks.

    参考文献
    相似文献
    引证文献
引用本文

张璐璐,杜学绘,王文娟.预训练模型与因果挖掘结合的多步攻击检测.计算机系统应用,,():1-13

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2026-03-02
  • 最后修改日期:2026-03-30
  • 录用日期:
  • 在线发布日期: 2026-08-21
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62661041 传真: Email:csa@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号