Construction of Cyber-attack Attribution Framework Based on LLM

Jingye Zhang, Ken Cheng, Xinli Xiong, Rongcheng Dong, Jun Huang, She Jie · 2024

The numerous cyber-attack attribution reports published by cybersecurity organizations serve as essential resources for studying and learning about attribution and are important references for conducting such activities. This paper introduces a hierarchical cyber-attack attribution framework and a method for filling the framework's content through the combined use of manual and large language model (LLM) analysis of cyber-attack attribution reports. Utilizing this approach, lengthy and complex reports can be efficiently analyzed, effectively extracting content for each level of the attribution framework. Since the framework's content is primarily built upon the analysis of a large number of attribution reports by an LLM, it ensures rich and objective framework content. Through the evaluation of the constructed framework, the results indicate that its content can effectively cover the attribution of the primary stages of network intrusions. Existing cyber-attack attribution frameworks often focus on providing macro-level guidance for attribution, whereas this framework includes detailed attribution methods and techniques, offering substantive knowledge support for attribution activities.

Read the paper · More papers on PaperTik