跳到主要导航 跳到搜索 跳到主要内容

TAA-EPLMR: Threat Actor Attribution via Evidence Path-Enhanced Large Language Model Reasoning

  • Nan Xiao
  • , Bo Lang*
  • , Yikai Chen
  • , Shuxin Zhao
  • , Yuhao Yan
  • *此作品的通讯作者
  • Beihang University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Threat actor attribution (TAA) is a complex task that requires multi-source intelligence fusion and semantic reasoning. In cyber threat intelligence (CTI) sharing, indicators of compromise (IOCs), with their diverse types and interconnections, provide critical evidence chains for TAA. However, existing methods primarily rely on small-scale intelligence data and embedding models, thereby limiting performance. Large language models (LLMs), with advanced semantic understanding and in-context learning capabilities, provide a promising approach to the complex semantic reasoning challenge in TAA. In this paper, we propose TAA-EPLMR, an evidence path-enhanced LLM reasoning approach that introduces a novel paradigm for TAA, cohesively integrating CTI knowledge graphs (CTIKGs) with large language models. We first define multi-level evidence path patterns (EPPs) grounded in CTI-based attribution semantics. We leverage these EPPs to retrieve candidate evidence paths from the CTI-KG, apply an attacker-discriminability-based pruning algorithm, and perform attacker-wise path aggregation to obtain refined evidence subgraphs for the candidate attackers. Furthermore, we design a chain of thought grounded in evidenceaware attribution logic and progressively challenging few-shot demonstrations. We prompt the LLM to infer threat actor attribution using the above information and generate attribution explanations along with confidence scores. Experiments on three datasets with varying completeness and noise levels consistently show that TAA-EPLMR outperforms all baselines and enhances the explainability and credibility of attribution reasoning.

源语言英语
主期刊名Proceedings - 2025 IEEE International Conference on Big Data, BigData 2025
编辑Cheng-Zhong Xu, Leong Hou U, Xueqi Cheng, Jing Gao, Giuseppe Polese, Hong Mei, Paul Boniol, Michiaki Tatsubori, Chen Zhao, Dawei Zhou, Xiaohua Hu
出版商Institute of Electrical and Electronics Engineers Inc.
2064-2073
页数10
版本2025
ISBN(电子版)9798331594473
DOI
出版状态已出版 - 2025
活动2025 IEEE International Conference on Big Data, BigData 2025 - Macau, 中国
期限: 8 12月 202511 12月 2025

会议

会议2025 IEEE International Conference on Big Data, BigData 2025
国家/地区中国
Macau
时期8/12/2511/12/25

指纹

探究 'TAA-EPLMR: Threat Actor Attribution via Evidence Path-Enhanced Large Language Model Reasoning' 的科研主题。它们共同构成独一无二的指纹。

引用此