The invention discloses an APT
attack detection method and device based on
traceability graph subgraph division of
mutual information approximation, equipment and a medium, and relates to the technical field of
network security, and the method comprises the steps: constructing an original
traceability graph comprising node attributes and edge attributes; performing representation learning by using a graph
convolutional neural network model to generate a low-dimensional node embedding vector; on the basis of a conditional scoring
function model, a node embedding vector is used as input, and in combination with context conditions,
conditional mutual information between nodes is approximately calculated; the context condition is determined according to the edge attribute; based on the condition
mutual information between the nodes, an optimization objective
function model is constructed, and sub-graph division of the original
traceability graph is completed; sub-graphs obtained through division are mapped to an existing
attack knowledge framework to be labeled, key nodes are recognized by calculating the contribution degree of nodes to
mutual information in the sub-graphs, a path formed by the key nodes is recognized as a key
attack chain, and a
visualization result and alarm information are generated. According to the method, the calculation efficiency, the robustness and the
interpretability are improved.