An APT Event Extraction Method Based on BERT-BiGRU-CRF for APT Attack Detection

被引:10
|
作者
Xiang, Ga [1 ]
Shi, Chen [1 ]
Zhang, Yangsen [1 ]
机构
[1] Beijing Informat Sci & Technol Univ, Sch Informat Management, Beijing 100192, Peoples R China
基金
中国国家自然科学基金;
关键词
network security; event extraction; deep learning; APT event; BERT-BiGRU-CRF;
D O I
10.3390/electronics12153349
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advanced Persistent Threat (APT) seriously threatens a nation's cyberspace security. Current defense technologies are typically unable to detect it effectively since APT attack is complex and the signatures for detection are not clear. To enhance the understanding of APT attacks, in this paper, a novel approach for extracting APT attack events from web texts is proposed. First, the APT event types and event schema are defined. Secondly, an APT attack event extraction dataset in Chinese is constructed. Finally, an APT attack event extraction model based on the BERT-BiGRU-CRF architecture is proposed. Comparative experiments are conducted with ERNIE, BERT, and BERT-BiGRU-CRF models, and the results show that the APT attack event extraction model based on BERT-BiGRU-CRF achieves the highest F1 value, indicating the best extraction performance. Currently, there is seldom APT event extraction research, the work in this paper contributes a new method to Cyber Threat Intelligence (CTI) analysis. By considering the multi-stages, complexity of APT attacks, and the data source from huge credible web texts, the APT event extraction method enhances the understanding of APT attacks and is helpful to improve APT attack detection capabilities.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] BERT-BIGRU-CRF: A Novel Entity Relationship Extraction Model
    Lv, Jianghai
    Du, Junping
    Zhou, Nan
    Xue, Zhe
    11TH IEEE INTERNATIONAL CONFERENCE ON KNOWLEDGE GRAPH (ICKG 2020), 2020, : 157 - 164
  • [2] Research on entity recognition and alignment of APT attack based on Bert and BiLSTM-CRF
    Yang, Xiuzhang
    Peng, Guojun
    Li, Zichuan
    Lyu, Yangqi
    Liu, Side
    Li, Chenguang
    Tongxin Xuebao/Journal on Communications, 2022, 43 (06): : 58 - 70
  • [3] Geotechnical Named Entity Recognition Based on BERT-BiGRU-CRF Model
    Quanyu W.
    Li Z.
    Tu Z.
    Chen G.
    Hu J.
    Chen J.
    Chen J.
    Lv G.
    Diqiu Kexue - Zhongguo Dizhi Daxue Xuebao/Earth Science - Journal of China University of Geosciences, 2023, 48 (08): : 3137 - 3150
  • [4] Research on Core Function of Adjacency Pairs Prediction Based on BERT-BIGRU-CRF
    Chen, Xin
    Qiu, Zhanzhi
    ACM International Conference Proceeding Series, 2021, : 117 - 121
  • [5] The APT Detection Method based on Attack Tree for SDN
    Jia Shan-Shan
    Xu Ya-Bin
    ICCSP 2018: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY, 2018, : 116 - 121
  • [6] An APT Attack Detection Method Based on eBPF and Transformer
    Qiu, Rixuan
    Luo, Hao
    Jing, Sitong
    Li, Xinxiu
    Li, Yuancheng
    International Journal of Network Security, 2024, 26 (06) : 964 - 972
  • [7] 基于BERT-BiGRU-CRF的医疗实体识别方法
    胡稳
    张云华
    计算机时代, 2023, (08) : 24 - 27
  • [8] A study on cyber threat prediction based on intrusion detection event for APT attack detection
    Kim, Yong-Ho
    Park, Won Hyung
    MULTIMEDIA TOOLS AND APPLICATIONS, 2014, 71 (02) : 685 - 698
  • [9] A study on cyber threat prediction based on intrusion detection event for APT attack detection
    Yong-Ho Kim
    Won Hyung Park
    Multimedia Tools and Applications, 2014, 71 : 685 - 698
  • [10] A BERT-BiGRU-CRF Model for Entity Recognition of Chinese Electronic Medical Records
    Qin, Qiuli
    Zhao, Shuang
    Liu, Chunmei
    COMPLEXITY, 2021, 2021