APTKG: Constructing Threat Intelligence Knowledge Graph from Open-Source APT Reports Based on Deep Learning

Lixiao Sun,Zitong Li,Lei Xie,Mai Ye,Bing Chen
DOI: https://doi.org/10.1109/dsit55514.2022.9943933
2022-01-01
Abstract:Advanced persistent threats (APTs) pose a serious threat to the security of cyberspace. Recently, more and more security organizations and vendors have been focusing on cyber threat intelligence (CTI) to tackle APTs. Particularly, some researchers have introduced knowledge graphs to aggregate CTIs and explore the potential intelligence value. This paper presents APTKG, a framework for automatically extracting CTI triples from open-source APT reports and constructing APT group- focused knowledge graphs. Specially, first, we model the STIX- based ontology, APTOnt, which aggregates malicious information from hierarchical levels and can be applied to threat hunting, group profiling, APT tracing and other tasks. Then, we propose a Multi-Feature based CTI recognition method to improve the accuracy of various CTIs extraction. Finally, we apply a BiGRU based Inter-Sentence method to extract document-level CTI relationships. The experimental results confirm that the proposed CTI entity recognition model and relationship extraction method exhibit excellent performance, and the joint model of the two is also effective for CTI triples extraction. In addition, APTKG has stimulated exploration and research on CTI-based APT attack defense and analysis.
What problem does this paper attempt to address?