An APT Event Extraction Method Based on BERT-BiGRU-CRF for APT Attack Detection

被引:10
作者
Xiang, Ga [1 ]
Shi, Chen [1 ]
Zhang, Yangsen [1 ]
机构
[1] Beijing Informat Sci & Technol Univ, Sch Informat Management, Beijing 100192, Peoples R China
基金
中国国家自然科学基金;
关键词
network security; event extraction; deep learning; APT event; BERT-BiGRU-CRF;
D O I
10.3390/electronics12153349
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advanced Persistent Threat (APT) seriously threatens a nation's cyberspace security. Current defense technologies are typically unable to detect it effectively since APT attack is complex and the signatures for detection are not clear. To enhance the understanding of APT attacks, in this paper, a novel approach for extracting APT attack events from web texts is proposed. First, the APT event types and event schema are defined. Secondly, an APT attack event extraction dataset in Chinese is constructed. Finally, an APT attack event extraction model based on the BERT-BiGRU-CRF architecture is proposed. Comparative experiments are conducted with ERNIE, BERT, and BERT-BiGRU-CRF models, and the results show that the APT attack event extraction model based on BERT-BiGRU-CRF achieves the highest F1 value, indicating the best extraction performance. Currently, there is seldom APT event extraction research, the work in this paper contributes a new method to Cyber Threat Intelligence (CTI) analysis. By considering the multi-stages, complexity of APT attacks, and the data source from huge credible web texts, the APT event extraction method enhances the understanding of APT attacks and is helpful to improve APT attack detection capabilities.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] An Event Timeline Extraction Method Based on News Corpus
    Wu, Yaguang
    Sun, Haichun
    Yan, Chungang
    2017 IEEE 2ND INTERNATIONAL CONFERENCE ON BIG DATA ANALYSIS (ICBDA), 2017, : 697 - 702
  • [22] DDoS Attack Detection Method Based on Machine Learning
    Liu, Cuilian
    Zhong, Sirong
    2024 IEEE 15TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE, ICSESS 2024, 2024, : 83 - 87
  • [23] PSO-GA Hyperparameter Optimized ResNet-BiGRU-Based Intrusion Detection Method
    Xia, Zhixin
    He, Siyuan
    Liu, Changwei
    Liu, Yongshan
    Yang, Xiaolei
    Bu, Huifeng
    IEEE ACCESS, 2024, 12 : 135535 - 135550
  • [24] An effective network attack detection method based on kernel PCA and LSTM-RNN
    Meng, Fanzhi
    Fu, Yunsheng
    Lou, Fang
    Chen, Zhiwen
    2017 INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS, ELECTRONICS AND CONTROL (ICCSEC), 2017, : 568 - 572
  • [25] CRF based method for Curb Detection using semantic cues and stereo depth
    Sodhi, Danish
    Upadhyay, Sarthak
    Bhatt, Dhaivat
    Krishna, K. Madhava
    Swarup, Shanti
    TENTH INDIAN CONFERENCE ON COMPUTER VISION, GRAPHICS AND IMAGE PROCESSING (ICVGIP 2016), 2016,
  • [26] DDoS Attack Detection Method Based on Linear Prediction Model
    Cheng, Jieren
    Yin, Jianping
    Wu, Chengkun
    Zhang, Boyun
    Liu, Yun
    EMERGING INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PROCEEDINGS, 2009, 5754 : 1004 - +
  • [27] A novel LDoS attack detection method based on reconstruction anomaly
    Tang, Dan
    Yan, Yudong
    Dai, Rui
    Qin, Zheng
    Chen, Jingwen
    Zhang, Dongshuo
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2022, 25 (02): : 1373 - 1392
  • [28] A DoS attack detection method based on adversarial neural network
    Li, Yang
    Wu, Haiyan
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [29] A novel LDoS attack detection method based on reconstruction anomaly
    Dan Tang
    Yudong Yan
    Rui Dai
    Zheng Qin
    Jingwen Chen
    Dongshuo Zhang
    Cluster Computing, 2022, 25 : 1373 - 1392
  • [30] LDoS attack detection method based on simple statistical features
    Duan X.
    Fu Y.
    Wang K.
    Li B.
    Tongxin Xuebao/Journal on Communications, 2022, 43 (11): : 53 - 64