摘要
Threat actor attribution (TAA) is a complex task that requires multi-source intelligence fusion and semantic reasoning. In cyber threat intelligence (CTI) sharing, indicators of compromise (IOCs), with their diverse types and interconnections, provide critical evidence chains for TAA. However, existing methods primarily rely on small-scale intelligence data and embedding models, thereby limiting performance. Large language models (LLMs), with advanced semantic understanding and in-context learning capabilities, provide a promising approach to the complex semantic reasoning challenge in TAA. In this paper, we propose TAA-EPLMR, an evidence path-enhanced LLM reasoning approach that introduces a novel paradigm for TAA, cohesively integrating CTI knowledge graphs (CTIKGs) with large language models. We first define multi-level evidence path patterns (EPPs) grounded in CTI-based attribution semantics. We leverage these EPPs to retrieve candidate evidence paths from the CTI-KG, apply an attacker-discriminability-based pruning algorithm, and perform attacker-wise path aggregation to obtain refined evidence subgraphs for the candidate attackers. Furthermore, we design a chain of thought grounded in evidenceaware attribution logic and progressively challenging few-shot demonstrations. We prompt the LLM to infer threat actor attribution using the above information and generate attribution explanations along with confidence scores. Experiments on three datasets with varying completeness and noise levels consistently show that TAA-EPLMR outperforms all baselines and enhances the explainability and credibility of attribution reasoning.
| 源语言 | 英语 |
|---|---|
| 主期刊名 | Proceedings - 2025 IEEE International Conference on Big Data, BigData 2025 |
| 编辑 | Cheng-Zhong Xu, Leong Hou U, Xueqi Cheng, Jing Gao, Giuseppe Polese, Hong Mei, Paul Boniol, Michiaki Tatsubori, Chen Zhao, Dawei Zhou, Xiaohua Hu |
| 出版商 | Institute of Electrical and Electronics Engineers Inc. |
| 页 | 2064-2073 |
| 页数 | 10 |
| 版本 | 2025 |
| ISBN(电子版) | 9798331594473 |
| DOI | |
| 出版状态 | 已出版 - 2025 |
| 活动 | 2025 IEEE International Conference on Big Data, BigData 2025 - Macau, 中国 期限: 8 12月 2025 → 11 12月 2025 |
会议
| 会议 | 2025 IEEE International Conference on Big Data, BigData 2025 |
|---|---|
| 国家/地区 | 中国 |
| 市 | Macau |
| 时期 | 8/12/25 → 11/12/25 |
指纹
探究 'TAA-EPLMR: Threat Actor Attribution via Evidence Path-Enhanced Large Language Model Reasoning' 的科研主题。它们共同构成独一无二的指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver