The invention provides an APT (
Advanced Persistent Threat)
attack detection method based on a large
language model, which comprises the following steps of: S1, extracting original
system call
event data from a kernel audit log of an
operating system, and preprocessing the data; s2, constructing a multi-model collaborative detection architecture based on a large
language model, and realizing fine-grained classification of network entities according to the preprocessed data through prompt construction, model
fine tuning and a confidence scoring mechanism; s3, constructing an adaptive graph
search algorithm based on multi-
modal feature correlation modeling, driving
attack path topology reconstruction, and realizing maximum reduction of a malicious sub-graph topology structure; s4, carrying out combination with MITRE ATTamp; the CK tactical
knowledge base constructs a cyclic enhancement analysis framework, a cyclic enhancement technology is adopted to drive a large
language model to execute hierarchical association reasoning, a mapping relation from malicious subgraphs to
attack tactics and tactical chains is derived step by step, and finally an attack report summary and a targeted defense strategy are generated. According to the invention, APT attack detection with high accuracy and high
interpretability is realized.