An attack skill and tactic identification method based on a topology-aware graph attention network

By using a method based on topology-aware graph attention network and persistent homology technology to mine multi-scale topological features in the MITRE ATT&CK framework, the problem of strong dependence on prior knowledge in existing technologies is solved, and the recognition accuracy and recall rate of APT attack TTPs are improved, making it suitable for complex network security scenarios.

CN120185857BActive Publication Date: 2025-10-17BEIJING UNIV OF POSTS & TELECOMM +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510240395.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-10-17
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

Existing technologies rely heavily on prior knowledge in the task of identifying TTPs of APT attacks, making it difficult to effectively capture label-level topological features, resulting in insufficient model generalization ability and low recognition accuracy.

Method used

A topology-aware graph attention network is used to mine multi-scale topological features in the MITRE ATT&CK framework through persistent homology technology. The graph attention network and multi-layer perceptron are combined for multi-label classification, and topological features are dynamically integrated with text representation to improve the recognition accuracy and recall rate of the model.

Benefits of technology

It significantly improves the accuracy and recall of TTPs identification, enhances the generalization ability of the model, and is suitable for diverse network security scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185857B_ABST
    Figure CN120185857B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for identifying attack techniques and tactics based on a topology-aware graph attention network. The method specifically includes the following steps: Step S1: preprocessing threat intelligence in the form of unstructured text; Step S2: extracting fine-grained semantic features using a text encoder and generating a high-dimensional embedding vector; Step S3: capturing the multi-scale topological information of the MITRE ATT&CK framework hierarchy using a topology-aware graph attention network and dynamically integrating the topological features into the text representation space; Step S4: finally, performing multi-label classification using a multi-layer perceptron combined with an adaptive threshold mechanism, and outputting TTPs identification results. This method overcomes the reliance of traditional multi-label text classification models on prior knowledge of labels by injecting high-order topological information inherent in the MITRE ATT&CK framework hierarchy into the textual representation of threat intelligence, thereby improving classification performance and generalization capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of network security, and particularly relates to an attack tactics and techniques identification method based on a topology-aware graph attention network. BACKGROUND

[0002] With the continuous evolution of network attack technology, modern network attacks have shown high industrialization and organization characteristics, and attack means are increasingly complex and diverse. Among them, as the most representative form of network attack, the persistence and concealment of advanced persistent threat (APT) pose unprecedented challenges to network security defense. To cope with APT attacks, a multi-level and multi-dimensional defense system needs to be built, and the core lies in the deep mining and analysis of APT-related threat intelligence. This involves the accurate identification and understanding of attacker tactics, techniques and procedures (TTPs). At present, the threat intelligence reports released by security vendors are the main source of TTPs information. These reports are usually presented in the form of unstructured natural language, and detailedly describe the behavior patterns, technical means and operation processes of attackers.

[0003] MITRE ATT&CK is a model that classifies adversary behaviors systematically, including various tactics, each tactic including various techniques, and each technique including various sub-techniques. In order to complete the identification of TTPs, the existing method usually regards the mapping of tactics and techniques as a text multi-label classification task, and uses the tactic and technique IDs in the MITRE ATT&CK framework as classification labels. Early studies mainly use traditional methods such as TF-IDF or Word2Vec for threat intelligence text representation, and combine machine learning algorithms such as support vector machine, decision tree and naive Bayes for multi-label classification. In recent years, deep learning methods have been gradually introduced into the TTPs identification task, for example, using a Transformer model for text representation, and introducing an attention mechanism and a recurrent structure to model the hierarchical relationship between ATT&CK tactics and techniques, thereby significantly improving the classification accuracy.

[0004] However, in the TTPs identification task, a sample can usually be classified into a set of labels with a hierarchical structure. Effective modeling of this hierarchy is key to achieving high-quality classification results, as it can intuitively express the complex relationships between labels. Existing hierarchical multi-label text classification methods still have the following limitations: (1) Existing methods usually rely on prior statistical information or pre-defined label representations, which requires the model to have a lot of domain knowledge, thus limiting the model's generalization ability. (2) Although graph neural networks are used in many hierarchical text classification methods to integrate hierarchical information, significantly improving classification accuracy and enhancing the model's ability to model hierarchical structures, their core mechanism is based on an iterative message passing scheme, which is difficult to effectively capture key topological features in the hierarchy (such as connectivity, loops, etc.). SUMMARY

[0005] To solve the problem of strong dependence on prior knowledge and difficulty in effectively capturing label hierarchy topological features in existing TTPs identification tasks, the present application proposes an attack technique and tactics identification method based on a topologically aware graph attention network. This method introduces the Persistent Homology technique without relying on prior statistical information or pre-defined label representations, fully exploiting the multi-scale topological features (such as connectivity) in the MITRE ATT&CK framework hierarchy, thereby significantly improving the accuracy, recall rate, and model generalization ability of TTPs identification. The present application takes advantage of the hierarchical nature of the MITRE ATT&CK label system to model the TTPs identification task as a hierarchical multi-label classification task. Specifically, by formalizing the label hierarchy as a non-connected graph and introducing a graph attention network based on Persistent Homology, the method captures the multi-scale topological features of the hierarchical label structure. By dynamically fusing topological features and text representations, the method enhances the vector representation of threat intelligence text, thereby significantly improving the precision, recall rate, and generalization ability of the TTPs identification task, providing an efficient and accurate solution for network security threat intelligence TTPs identification.

[0006] The technical solution adopted by the present application to solve its technical problems is: an attack technique and tactics identification method based on a topologically aware graph attention network is proposed, comprising the following steps:

[0007] S1, preprocessing unstructured text-form threat intelligence data to remove redundant, irrelevant, or duplicate information, performing text cleaning, word segmentation, entity standardization, etc., to obtain standardized threat intelligence text;

[0008] S2, using a text encoder (such as TextRCNN or a pre-trained language model Bert) to encode the preprocessed text data, extracting fine-grained semantic features and generating high-dimensional embedding vectors H;

[0009] S3, using a topology-aware graph attention network, mapping the embedding vector H of the text to the initial feature X of the graph node according to the hierarchy G of the MITRE ATT&CK framework G ; first input it into the graph attention network to aggregate neighbor node information, input the refined graph node representation Z, and then generate a multi-view graph set S through node mapping G ; perform a graph filtering operation on each graph in S G ; construct a Vietoris-Rips complex and calculate the persistent homology feature; generate a persistence diagram (PD), where the horizontal axis represents the birth time of the topological feature, the vertical axis represents the death time, each point corresponds to the birth and death time of a connected component or ring structure, and the distance between points represents the duration of the structure; then apply an embedding function Ψ (such as a Gaussian kernel transformation) to convert the PD into a topological vector H topo , and finally adaptively weight and fuse it with the attention-refined node embedding Z to obtain the final vector representation H T ;

[0010] S4, complete multi-label classification through a multilayer perceptron (MLP) combined with an adaptive threshold mechanism, and output TTPs recognition results.

[0011] Compared with the prior art, the beneficial effects of the present application are:

[0012] 1. The topology-aware enhanced graph attention network constructed by the present application can effectively integrate the topological structure information of the ATT&CK framework itself, capture the multi-scale topological features of the ATT&CK framework hierarchy using persistent homology technology, and enhance the modeling ability of the model for complex hierarchical relationships.

[0013] 2. By dynamically fusing topological features into the text representation space, the present application significantly improves the accuracy and recall rate of TTPs recognition, especially when facing complex and multi-level ATT&CK label systems.

[0014] 3. The present application does not rely on prior statistical information or pre-defined label representation, reduces the dependence of the model on domain knowledge, and thus improves the generalization ability of the model, which is suitable for diversified network security scenarios. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments or the prior art, the drawings needed in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments described in the present application, and other drawings can also be obtained by those skilled in the art according to these drawings.

[0016] Figure 1 A flow chart of an attack technique and tactic method based on a topology-aware graph attention network is provided for an embodiment of the present application.

[0017] Figure 2 A hierarchical diagram of the tactic TA002: Execution and its part techniques in the MITRE ATT&CK framework.

[0018] Figure 3 A model architecture diagram of an attack technique and tactic recognition model based on a topology-aware graph attention network is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0019] In order to better understand the technical solutions, the method of the present application will be described in detail below in combination with the drawings and specific implementations.

[0020] REFERENCE Figure 1 The attack technique and tactic recognition method based on a topology-aware graph attention network proposed in the present application includes the following steps:

[0021] S1, processing the threat intelligence text in an unstructured text form, specifically including the following sub-steps:

[0022] S11, text cleaning: removing redundant information such as HTML tags, special symbols, stop words, etc., and using regular expressions to match common threat intelligence indicators (Indicators of Compromise, IOC), such as IP addresses, domain names, file hashes, etc., and replacing them with uniform identifiers according to their types (for example, replacing IP addresses with [IP], and replacing file hashes with [HASH]);

[0023] S12, entity standardization: aligning the entities in the sentence with the standard terms in the MITRE ATT&CK framework, for example, mapping “remote control” to “Remote Control”;

[0024] S13, irrelevant text filtering: using a One-Class SVM algorithm to filter the collected sentences, filtering out sentences unrelated to attack behavior, and retaining key text content related to TTPs.

[0025] S2, using a text encoder to encode the preprocessed text data, extracting fine-grained semantic features and generating high-dimensional embedding vectors H, specifically including the following sub-steps:

[0026] S21, convert the preprocessed text into a word vector sequence, use a pre-trained word embedding model (such as Word2Vec, GloVe, etc.) or directly use a pre-trained language model (such as BERT, RoBERTa) for initialization;

[0027] S22, feature extraction: if using TextRCNN encoder, first capture the context information of the text through bidirectional GRU, then use convolutional neural network (CNN) to extract local n-gram features, and finally generate fixed-length text representation through max-pooling; if using BERT encoder, input the text into BERT model, and extract the hidden state of [CLS] position as the global representation of the text;

[0028] S23, map the extracted text features to high-dimensional vectors H as the input of the subsequent topology-aware attention network.

[0029] S3, use a graph attention network based on topology-aware enhancement to capture the multi-scale topology information of the ATT&CK framework hierarchy, dynamically integrate the topology features into the text representation space, and obtain the enhanced vector representation as H T , which includes the following sub-steps:

[0030] S31, restate the hierarchy of MITRE ATT&CK framework as an undirected non-connected graph G=(V G ,E G ,X G ), where V G and E G represent the node set and edge set of graph G respectively, node v∈V represents the tactic / technique label, and E G is the connection relationship between techniques and tactics in MITRE ATT&CK. X G is the node embedding matrix of G. Instead of learning the concept of labels, we directly broadcast the text representation to the label structure. Specifically, X G is converted from the text representation H through projection. Formally,

[0031] X G =HW H +B H (1)

[0032] where is the learning weight for copying and projection, d H and d V represent the dimensions of the text and nodes respectively. B H represents the learnable bias term, and |Y| is the size of the TTPs label set;

[0033] S32, embedding the nodes into a matrix X G and the hierarchical information of MITRE ATT&CK framework as input, the weight between nodes is calculated by the multi-head attention mechanism of graph attention network, the information of neighbor nodes is aggregated, and the refined node embedding Z∈R N×d is generated, where N represents the number of vertices, and d represents the dimension of the hidden embedding of each vertex.

[0034] S33, as Figure 3 shown, performing multi-scale topological analysis on the graph representation obtained in step S23, extracting connectivity, loop and other high-order topological features in the label hierarchy by persistent homology technology, generating a persistent diagram (PD), and converting the persistent diagram into a topological vector H topo using an embedding function.

[0035] S34, dynamically fusing the extracted topological features H topo and the refined node embedding Z to generate an enhanced vector representation H T , and the specific formula is:

[0036] H T = H topo + αZ (2)

[0037] where α is the fusion weight, and H topo is the topological features extracted from the graph G.

[0038] S4, completing multi-label classification by multi-layer perception combined with adaptive threshold mechanism, and outputting the TTPs recognition result, specifically including the following sub-steps:

[0039] S41, inputting the enhanced vector representation H T into the MLP, gradually reducing the dimension through fully connected layers and nonlinear activation functions, and generating low-dimensional classification features;

[0040] S42, calculating the probability score P of each label by using the Sigmoid function, and for multi-label classification,

[0041] S43, dynamically adjusting the classification threshold according to the label distribution of the training data, to ensure that the prediction result of each label has high accuracy and recall rate;

[0042] S44, taking the label with a probability score higher than the threshold as the final prediction result, and outputting the TTPs recognition result. Further, S33 specifically includes:

[0043] The original graph G is converted into a set of k graphs , where each graph corresponds to the vector representation under the i-th perspective.

[0044] Then, for each transformed graph S i The information of nodes and edges of each view is processed step by step by applying graph filtering operation. The filtering process of graph can be described as:

[0045]

[0046] where, and denote the node set and edge set of graph S i at the i-th view and the j-th filtering level.

[0047] The graph filtering process decides which nodes and edges to keep by setting a threshold. Specifically, if the embedding z v of a node v is smaller than the threshold i after passing through the pooling function f , then the node and its connected edges will be kept. The filtering rules of nodes and edges are as follows:

[0048]

[0049] Then, the evolution of topological features is calculated using persistent homology, and the time interval of the appearance and disappearance of features in the simplicial complex is recorded, denoted as the birth time b and the death time d; these cycles are usually represented by persistent diagrams (PD), which are a set of points in a two-dimensional plane, where each point (b, d) represents a persistent homology class of dimension l that appears at time b and disappears at time d (dimension l = 0, 1, 2 correspond to connected components, loops and voids, respectively). For the TTPs identification problem, we only consider connected components, i.e. l = 0.

[0050] Finally, we convert the persistent diagram into a topological vector H topo using the embedding function Ψ, which can be represented as:

[0051]

[0052] where k is the number of views of the graph, n represents the number of vertices, d represents the dimension of the topological vector, denotes the persistent diagram obtained by persistent homology of graph S i .

[0053] The embodiments of the present application are described in detail above with reference to the drawings, but the present application is not limited to the above-described embodiments, and for those skilled in the art, after learning the content described in the present application, without departing from the principles of the present application, a number of equivalent transformations and substitutions can be made, which should be considered as belonging to the protection scope of the present application.

Claims

1. A method for identifying attack techniques and tactics based on a topological perception graph attention network, characterized in that: The following steps are involved: S1. Preprocess unstructured threat intelligence data in text form to remove redundant, irrelevant, or repeated information, perform text cleaning, word segmentation, and entity standardization operations to obtain standardized threat intelligence text. S2. Use a text encoder to encode the preprocessed text data, extract fine-grained semantic features and generate a high-dimensional embedding vector H; S3. Use a topology-aware graph attention network to map the text embedding vector H to the initial features X of the graph nodes according to the hierarchical structure G of the MITRE ATT&CK framework. G First, it is input into the graph attention network to aggregate neighbor node information, and then the refined graph node representation Z is input. Then, the multi-view graph set S is generated through node mapping. G ; for S G Perform a graph filtering operation on each graph in the graph, construct a Vietoris-Rips complex and calculate the persistent homology feature; generate a persistence graph, where the horizontal axis represents the birth time of the topological feature and the vertical axis represents the extinction time. Each point corresponds to the birth and death time of a connected component or ring structure, and the distance between the points represents the duration of the structure; then apply the embedding function Ψ to convert the persistence graph into a topological vector H topo Finally, it is adaptively weighted fused with the node embedding Z after attention refinement to obtain the final vector representation H T ; S4. Complete multi-label classification through a multi-layer perceptron combined with an adaptive threshold mechanism and output TTPs recognition results.

2. The method according to claim 1, characterized in that Step S1 specifically includes the following sub-steps: S11. Text cleaning: Remove HTML tags, special symbols, and stop words. Use regular expressions to match common threat intelligence indicators and replace them with unified identifiers based on their types. S12, Entity Standardization: Align entities in sentences with standard terminology in the MITRE ATT&CK framework; S13. Irrelevant text filtering: Use the One-Class SVM algorithm to filter the collected sentences, filter out sentences irrelevant to the attack behavior, and retain the key text content related to TTPs.

3. The method according to claim 1, characterized in that Step S2 includes the following sub-steps: S21. Convert the preprocessed text into a word vector sequence and initialize it using the pre-trained word embedding model GloVe or directly using the pre-trained language model BERT; S22. Feature extraction: If the TextRCNN encoder is used, the context of the text is first captured through a bidirectional GRU, then a convolutional neural network is used to extract local n-gram features, and finally a fixed-length text representation is generated through max pooling. If the BERT encoder is used, the text is input into the BERT model and the hidden state at the [CLS] position is extracted as the global representation of the text. S23. Map the extracted text features into a high-dimensional vector H as the input of the subsequent topology-aware attention network.

4. The method according to claim 1, wherein Step S3 specifically includes the following sub-steps: S31. Re-express the hierarchical structure of the MITRE ATT&CK framework as an undirected non-connected graph G = (V G ,E G ,X G ), where V G and E G denote the node set and edge set of the graph G, respectively. Node v∈V denotes a tactical / technical label, and E G That is, the connection between technology and tactics in ATT&CK, the node feature matrix X G It is generated from the threat intelligence text embedding vector H through a projection operation; S32, embed the node into matrix X G and the hierarchical structure information of the MITRE ATT&CK framework as input, the multi-head attention mechanism of the graph attention network is used to calculate the weights between nodes, aggregate the information of neighboring nodes, and generate the refined node embedding Z∈R N×d , where N represents the number of vertices and d represents the dimension of the hidden embedding of each vertex; S33, perform multi-scale topological analysis on the graph representation obtained in step S23, extract the connectivity and high-order topological features of the ring in the label hierarchy through persistent homology technology, generate a persistent graph, and use the embedding function to convert the persistent graph into a topological vector H topo ; S34, extract the topological features H topo Dynamically fused with node embedding Z to generate enhanced vector representation H T .

5. The method according to claim 4, characterized in that: In step S33, the original graph G is converted into a set of k graphs Each of the graphs Corresponding to the node embedding under the i-th perspective; Then, for each transformed graph S i Applying graph filtering operations, we gradually process the node and edge information of each perspective. The graph filtering process can be described as follows: in and Indicates that the filtering degree is j at the i-th perspective. i The graph filtering process determines which nodes and edges to retain by setting a threshold. Specifically, if the embedding z of node v v After the pooling function f i (·) is less than the threshold The node and its connected edges will be retained; the filtering rules for nodes and edges are as follows: Then, we use persistent homology to calculate the evolution of topological features and record the time intervals when features appear and disappear in the simplicial complex, which are recorded as birth time b and death time d respectively. These cycles are represented by persistence graphs (PD), which are a set of points on a two-dimensional plane, where each point (b, d) represents a persistent homology class of dimension l that appears at time b and disappears at time d, with dimensions l = 0, 1, and 2 corresponding to connected components, cycles, and holes, respectively. For the TTPs identification problem, only connected components are considered, that is, l = 0. Finally, the persistence graph PD is converted into a topological vector using the embedding function Ψ. This process is expressed as: Where k is the number of views of the graph, N is the number of vertices, and d is the dimension of the topological vector. Representation Figure S i The persistence graph obtained through persistent homology.

6. The method according to claim 4, characterized in that: Step S34 uses the weighted fusion method to extract the topological features H topo Dynamically fused with the refined node embedding Z to generate an enhanced vector representation H T , this process is expressed as: Among them, α is the fusion weight coefficient obtained through learning, H topo is the topological feature extracted from the graph G, Z is the refined node embedding, and the weighted fusion process automatically adjusts the contribution of topological features and node embedding through the learned α.

Citation Information

Patent Citations

  • Intelligent big data acquisition and analysis method and system based on deep learning

    CN119004072A

  • Scene perception trust evaluation method based on graph neural network

    CN119254640A