<p>Advanced persistent threat (APT) attribution is a key defense strategy that can effectively safeguard the security of critical assets and systems. Cyber threat intelligence (CTI) contains rich information about APT groups that can be leveraged for attribution. However, most existing studies focus on a single feature from different perspectives, neglecting the multi-level mining and combined features of CTI, which limits the depth and accuracy of attribution analysis and may even lead to misleading conclusions. To overcome these limitations, we propose a multi-level feature Dempster–Shafer joint (MLDSJ) attribution method for APT groups based on threat intelligence. Specifically, we extract multi-level features such as attack patterns, textual information, and graph topology from CTI reports to construct feature vectors. Subsequently, we classify the three types of features separately using simple machine learning models. Finally, we introduce Dempster–Shafer (DS) evidence theory and apply the Dempster combination rule to integrate the three feature types and determine the final attribution. Experimental results show that our method outperforms the baseline in classification, achieving an accuracy of 89.9%, a recall of 86.5%, and an F1-score of 88.2%. These findings highlight the value of multi-level feature fusion in enhancing APT attribution performance and provide new insights into the design of intelligence-driven defense strategies.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

MLDSJ: a multi-level feature joint attribution method for APT group based on threat intelligence

  • Longxuan Duan,
  • Mi Wen,
  • Yun Xiong

摘要

Advanced persistent threat (APT) attribution is a key defense strategy that can effectively safeguard the security of critical assets and systems. Cyber threat intelligence (CTI) contains rich information about APT groups that can be leveraged for attribution. However, most existing studies focus on a single feature from different perspectives, neglecting the multi-level mining and combined features of CTI, which limits the depth and accuracy of attribution analysis and may even lead to misleading conclusions. To overcome these limitations, we propose a multi-level feature Dempster–Shafer joint (MLDSJ) attribution method for APT groups based on threat intelligence. Specifically, we extract multi-level features such as attack patterns, textual information, and graph topology from CTI reports to construct feature vectors. Subsequently, we classify the three types of features separately using simple machine learning models. Finally, we introduce Dempster–Shafer (DS) evidence theory and apply the Dempster combination rule to integrate the three feature types and determine the final attribution. Experimental results show that our method outperforms the baseline in classification, achieving an accuracy of 89.9%, a recall of 86.5%, and an F1-score of 88.2%. These findings highlight the value of multi-level feature fusion in enhancing APT attribution performance and provide new insights into the design of intelligence-driven defense strategies.