基于时空属性推理和对抗性负抽样的小规模APT知识图谱嵌入

IF 2.3 Q2 COMPUTER SCIENCE, THEORY & METHODS
Array Pub Date : 2025-05-14 DOI:10.1016/j.array.2025.100404
Yushun Xie , Haiyan Wang , Xiao Jing , Zhaoquan Gu
{"title":"基于时空属性推理和对抗性负抽样的小规模APT知识图谱嵌入","authors":"Yushun Xie ,&nbsp;Haiyan Wang ,&nbsp;Xiao Jing ,&nbsp;Zhaoquan Gu","doi":"10.1016/j.array.2025.100404","DOIUrl":null,"url":null,"abstract":"<div><div>Advanced Persistent Threat (APT) represents a class of highly sophisticated and stealthy cyberattacks that pose significant challenges to traditional defense mechanisms. Knowledge Graph Embedding (KGE) techniques provide a promising approach for APT attack prediction by leveraging existing cybersecurity knowledge to infer potential attack behaviors. However, the effectiveness of existing KGE methods is severely hindered by the scarcity of APT attack knowledge and the sparsity of knowledge graph connectivity, resulting in suboptimal knowledge representation and predictive performance. We propose an enhanced APT knowledge graph embedding method called APT-ST-AN to address the limitations of incomplete and sparse data in small-scale APT knowledge graphs. The proposed model introduces spatio-temporal attribute reasoning to enrich positive APT attack examples, thereby expanding the knowledge base with inferred attack patterns. At the same time, the model utilizes adversarial negative sampling, combining adversarial example generation with synthetic example creation to produce high-quality negative examples that improve the training process of the model. By jointly expanding the APT knowledge from both positive and negative examples, APT-ST-AN improves the expressiveness and generalization of KGE models. Extensive experiments on multiple small-scale APT knowledge graphs demonstrate that APT-ST-AN consistently outperforms existing compared models. Notably, APT-ST-AN achieves a maximum Mean Reciprocal Rank (MRR) of 0.589 and Hits@10 of 0.673, yielding up to a 38.3% improvement over baseline methods. These results demonstrate that APT-ST-AN exhibits high predictive accuracy in APT attack inference, thereby enhancing the ability of cybersecurity systems to anticipate and mitigate sophisticated cyber threats.</div></div>","PeriodicalId":8417,"journal":{"name":"Array","volume":"26 ","pages":"Article 100404"},"PeriodicalIF":2.3000,"publicationDate":"2025-05-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Enhanced small-scale APT knowledge graph embedding via spatio-temporal attribute reasoning and adversarial negative sampling\",\"authors\":\"Yushun Xie ,&nbsp;Haiyan Wang ,&nbsp;Xiao Jing ,&nbsp;Zhaoquan Gu\",\"doi\":\"10.1016/j.array.2025.100404\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>Advanced Persistent Threat (APT) represents a class of highly sophisticated and stealthy cyberattacks that pose significant challenges to traditional defense mechanisms. Knowledge Graph Embedding (KGE) techniques provide a promising approach for APT attack prediction by leveraging existing cybersecurity knowledge to infer potential attack behaviors. However, the effectiveness of existing KGE methods is severely hindered by the scarcity of APT attack knowledge and the sparsity of knowledge graph connectivity, resulting in suboptimal knowledge representation and predictive performance. We propose an enhanced APT knowledge graph embedding method called APT-ST-AN to address the limitations of incomplete and sparse data in small-scale APT knowledge graphs. The proposed model introduces spatio-temporal attribute reasoning to enrich positive APT attack examples, thereby expanding the knowledge base with inferred attack patterns. At the same time, the model utilizes adversarial negative sampling, combining adversarial example generation with synthetic example creation to produce high-quality negative examples that improve the training process of the model. By jointly expanding the APT knowledge from both positive and negative examples, APT-ST-AN improves the expressiveness and generalization of KGE models. Extensive experiments on multiple small-scale APT knowledge graphs demonstrate that APT-ST-AN consistently outperforms existing compared models. Notably, APT-ST-AN achieves a maximum Mean Reciprocal Rank (MRR) of 0.589 and Hits@10 of 0.673, yielding up to a 38.3% improvement over baseline methods. These results demonstrate that APT-ST-AN exhibits high predictive accuracy in APT attack inference, thereby enhancing the ability of cybersecurity systems to anticipate and mitigate sophisticated cyber threats.</div></div>\",\"PeriodicalId\":8417,\"journal\":{\"name\":\"Array\",\"volume\":\"26 \",\"pages\":\"Article 100404\"},\"PeriodicalIF\":2.3000,\"publicationDate\":\"2025-05-14\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Array\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2590005625000311\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, THEORY & METHODS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Array","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2590005625000311","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, THEORY & METHODS","Score":null,"Total":0}
引用次数: 0

摘要

高级持续性威胁(APT)是一类高度复杂和隐蔽的网络攻击,对传统防御机制构成重大挑战。知识图嵌入(KGE)技术通过利用现有的网络安全知识来推断潜在的攻击行为,为APT攻击预测提供了一种很有前途的方法。然而,现有的KGE方法的有效性受到APT攻击知识的稀缺性和知识图连通性的稀缺性的严重影响,导致知识表示和预测性能不理想。针对小规模APT知识图中数据不完整和稀疏的局限性,提出了一种增强的APT知识图嵌入方法APT- st - an。该模型引入时空属性推理来丰富APT攻击实例,从而通过推断攻击模式扩展知识库。同时,该模型利用对抗性负抽样,将对抗性样例生成与合成样例创建相结合,生成高质量的负样例,提高了模型的训练过程。APT- st - an通过正例和反例共同扩展APT知识,提高了KGE模型的表达能力和泛化能力。在多个小规模APT知识图上进行的大量实验表明,APT- st - an始终优于现有的比较模型。值得注意的是,APT-ST-AN的最大平均倒数秩(MRR)为0.589,Hits@10为0.673,比基线方法提高了38.3%。这些结果表明,APT- st - an在APT攻击推理中表现出很高的预测准确性,从而增强了网络安全系统预测和缓解复杂网络威胁的能力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Enhanced small-scale APT knowledge graph embedding via spatio-temporal attribute reasoning and adversarial negative sampling
Advanced Persistent Threat (APT) represents a class of highly sophisticated and stealthy cyberattacks that pose significant challenges to traditional defense mechanisms. Knowledge Graph Embedding (KGE) techniques provide a promising approach for APT attack prediction by leveraging existing cybersecurity knowledge to infer potential attack behaviors. However, the effectiveness of existing KGE methods is severely hindered by the scarcity of APT attack knowledge and the sparsity of knowledge graph connectivity, resulting in suboptimal knowledge representation and predictive performance. We propose an enhanced APT knowledge graph embedding method called APT-ST-AN to address the limitations of incomplete and sparse data in small-scale APT knowledge graphs. The proposed model introduces spatio-temporal attribute reasoning to enrich positive APT attack examples, thereby expanding the knowledge base with inferred attack patterns. At the same time, the model utilizes adversarial negative sampling, combining adversarial example generation with synthetic example creation to produce high-quality negative examples that improve the training process of the model. By jointly expanding the APT knowledge from both positive and negative examples, APT-ST-AN improves the expressiveness and generalization of KGE models. Extensive experiments on multiple small-scale APT knowledge graphs demonstrate that APT-ST-AN consistently outperforms existing compared models. Notably, APT-ST-AN achieves a maximum Mean Reciprocal Rank (MRR) of 0.589 and Hits@10 of 0.673, yielding up to a 38.3% improvement over baseline methods. These results demonstrate that APT-ST-AN exhibits high predictive accuracy in APT attack inference, thereby enhancing the ability of cybersecurity systems to anticipate and mitigate sophisticated cyber threats.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Array
Array Computer Science-General Computer Science
CiteScore
4.40
自引率
0.00%
发文量
93
审稿时长
45 days
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信