Threat detection method and system based on trace graph behavior semantics extraction
By constructing an interest subgraph based on the source graph and assigning text descriptions to event edges and entity nodes, and by utilizing NLP technology and detection models, the shortcomings of existing threat detection systems in identifying hidden attack behaviors are addressed, achieving higher detection accuracy and more interpretable alerts.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIHANG UNIV
- Filing Date
- 2023-08-25
- Publication Date
- 2026-05-29
AI Technical Summary
Existing threat detection systems struggle to effectively identify attacks hidden within normal behavior, lack a holistic consideration and semantic representation of attack behavior, resulting in high false alarm rates, poor detection performance, and a lack of interpretability in alert results.
Interest subgraphs are constructed based on the source graph, text descriptions are assigned to event edges and entity nodes using NLP technology, the nature of behavior is determined by the detection model, and the detection accuracy is improved by combining semantic rules and training data.
It improves the accuracy of threat detection and the analytical capabilities of security analysts, effectively identifying attack behaviors and providing interpretable alert results.
Smart Images

Figure CN116938587B_ABST