An APT Event Extraction Method Based on BERT-BiGRU-CRF for APT Attack Detection

被引:10
作者
Xiang, Ga [1 ]
Shi, Chen [1 ]
Zhang, Yangsen [1 ]
机构
[1] Beijing Informat Sci & Technol Univ, Sch Informat Management, Beijing 100192, Peoples R China
基金
中国国家自然科学基金;
关键词
network security; event extraction; deep learning; APT event; BERT-BiGRU-CRF;
D O I
10.3390/electronics12153349
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advanced Persistent Threat (APT) seriously threatens a nation's cyberspace security. Current defense technologies are typically unable to detect it effectively since APT attack is complex and the signatures for detection are not clear. To enhance the understanding of APT attacks, in this paper, a novel approach for extracting APT attack events from web texts is proposed. First, the APT event types and event schema are defined. Secondly, an APT attack event extraction dataset in Chinese is constructed. Finally, an APT attack event extraction model based on the BERT-BiGRU-CRF architecture is proposed. Comparative experiments are conducted with ERNIE, BERT, and BERT-BiGRU-CRF models, and the results show that the APT attack event extraction model based on BERT-BiGRU-CRF achieves the highest F1 value, indicating the best extraction performance. Currently, there is seldom APT event extraction research, the work in this paper contributes a new method to Cyber Threat Intelligence (CTI) analysis. By considering the multi-stages, complexity of APT attacks, and the data source from huge credible web texts, the APT event extraction method enhances the understanding of APT attacks and is helpful to improve APT attack detection capabilities.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] BERT-Based Joint Model for Aspect Term Extraction and Aspect Polarity Detection in Arabic Text
    Chouikhi, Hasna
    Alsuhaibani, Mohammed
    Jarray, Fethi
    ELECTRONICS, 2023, 12 (03)
  • [32] A Method for Judicial Case Knowledge Graph Construction Based on Event Extraction
    Zhao, Bang
    Zhao, Yilong
    Mao, Ying
    PROCEEDINGS OF THE 2024 9TH INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION TECHNOLOGY, ICIIT 2024, 2024, : 62 - 69
  • [33] Generating Chinese Event Extraction Method Based on ChatGPT and Prompt Learning
    Chen, Jianxun
    Chen, Peng
    Wu, Xuxu
    APPLIED SCIENCES-BASEL, 2023, 13 (17):
  • [34] Low-rate DoS attack detection method based on hybrid deep neural networks
    Xu, Congyuan
    Shen, Jizhong
    Du, Xin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 60
  • [35] An Entropy-based Method for Attack Detection in Large Scale Network
    Liu, T.
    Wang, Z.
    Wang, H.
    Lu, K.
    INTERNATIONAL JOURNAL OF COMPUTERS COMMUNICATIONS & CONTROL, 2012, 7 (03) : 509 - 517
  • [36] Audit Method Based on Event Extraction and Verification Warning for Power Engineering Projects
    Sui, Aifang
    Ding, Pengcheng
    2024 9TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS, ICCCS 2024, 2024, : 1265 - 1271
  • [37] A biomedical event extraction method based on fine-grained and attention mechanism
    Xinyu He
    Ping Tai
    Hongbin Lu
    Xin Huang
    Yonggong Ren
    BMC Bioinformatics, 23
  • [38] A biomedical event extraction method based on fine-grained and attention mechanism
    He, Xinyu
    Tai, Ping
    Lu, Hongbin
    Huang, Xin
    Ren, Yonggong
    BMC BIOINFORMATICS, 2022, 23 (01)
  • [39] A multiple distributed representation method based on neural network for biomedical event extraction
    Anran Wang
    Jian Wang
    Hongfei Lin
    Jianhai Zhang
    Zhihao Yang
    Kan Xu
    BMC Medical Informatics and Decision Making, 17
  • [40] A multiple distributed representation method based on neural network for biomedical event extraction
    Wang, Anran
    Wang, Jian
    Lin, Hongfei
    Zhang, Jianhai
    Yang, Zhihao
    Xu, Kan
    BMC MEDICAL INFORMATICS AND DECISION MAKING, 2017, 17