APT Attack Detection with Heterogeneous Provenance Graph and Adversarial Knowledge of Tactics, Techniques, and Procedures
摘要
Advanced Persistent Threats (APTs) pose significant challenges due to their stealthy, multi-stage nature and resistance to traditional detection methods. This paper proposes a Meta-path Aggregated Graph for APT detection (MAGAPT) framework that integrates heterogeneous provenance graphs (HPGs) with structured threat knowledge of adversarial tactics, techniques, and procedures (TTPs) from the MITRE ATT&CK framework. By embedding tactic–technique relationships as semantic knowledge edges, we construct an Enhanced Heterogeneous Provenance Graph (EHPG) that captures both system-level interactions and high-level adversarial intent. Moreover, a Metapath Aggregated Graph Neural Network (MAGNN) is employed to learn contextualized representations for classification. Experimental results on DARPA OpTC and TC3 (CADETS) datasets show that our approach outperforms baseline models and state-of-the-art (SOTA) methods in detection accuracy and generalization, demonstrating the effectiveness of knowledge-aware heterogeneous graph learning for advanced threat detection.