Abstract
Threat actor attribution (TAA) is a complex task that requires multi-source intelligence fusion and semantic reasoning. In cyber threat intelligence (CTI) sharing, indicators of compromise (IOCs), with their diverse types and interconnections, provide critical evidence chains for TAA. However, existing methods primarily rely on small-scale intelligence data and embedding models, thereby limiting performance. Large language models (LLMs), with advanced semantic understanding and in-context learning capabilities, provide a promising approach to the complex semantic reasoning challenge in TAA. In this paper, we propose TAA-EPLMR, an evidence path-enhanced LLM reasoning approach that introduces a novel paradigm for TAA, cohesively integrating CTI knowledge graphs (CTIKGs) with large language models. We first define multi-level evidence path patterns (EPPs) grounded in CTI-based attribution semantics. We leverage these EPPs to retrieve candidate evidence paths from the CTI-KG, apply an attacker-discriminability-based pruning algorithm, and perform attacker-wise path aggregation to obtain refined evidence subgraphs for the candidate attackers. Furthermore, we design a chain of thought grounded in evidenceaware attribution logic and progressively challenging few-shot demonstrations. We prompt the LLM to infer threat actor attribution using the above information and generate attribution explanations along with confidence scores. Experiments on three datasets with varying completeness and noise levels consistently show that TAA-EPLMR outperforms all baselines and enhances the explainability and credibility of attribution reasoning.
| Original language | English |
|---|---|
| Title of host publication | Proceedings - 2025 IEEE International Conference on Big Data, BigData 2025 |
| Editors | Cheng-Zhong Xu, Leong Hou U, Xueqi Cheng, Jing Gao, Giuseppe Polese, Hong Mei, Paul Boniol, Michiaki Tatsubori, Chen Zhao, Dawei Zhou, Xiaohua Hu |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 2064-2073 |
| Number of pages | 10 |
| Edition | 2025 |
| ISBN (Electronic) | 9798331594473 |
| DOIs | |
| State | Published - 2025 |
| Event | 2025 IEEE International Conference on Big Data, BigData 2025 - Macau, China Duration: 8 Dec 2025 → 11 Dec 2025 |
Conference
| Conference | 2025 IEEE International Conference on Big Data, BigData 2025 |
|---|---|
| Country/Territory | China |
| City | Macau |
| Period | 8/12/25 → 11/12/25 |
Keywords
- Cyber Threat Intelligence
- Evidence Path Retrieval Augmentation
- Indicators of Compromise
- Large Language Model Reasoning
- Threat Actor Attribution
Fingerprint
Dive into the research topics of 'TAA-EPLMR: Threat Actor Attribution via Evidence Path-Enhanced Large Language Model Reasoning'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver