Construction of Domain-Specific Knowledge Graph for Advanced Persistent Threat Behaviour Analysis and Detection

Yitian Yang, Huaming Chen · 2025

Advanced Persistent Threat (APT) represents a sophisticated and targeted attack campaign, often orchestrated by well-resourced organizations. Understanding APT is crucial for adapting to their evolving tactics and effectively mitigating their infiltration methods. A key approach to accurately analysing and detecting APTs involves studying the behaviour, identifying their attack stage and uncovering the employed components. Existing works for APT detection heavily rely on network traffic analysis, limiting their practical applicability in real-world scenarios. This paper introduces a novel method to analyse and detect APT behaviours by constructing a domain-specific knowledge graph (APT-KG), utilising the MITRE ATT&CK framework as its foundation. A hierarchical clustering-based model is proposed to uncover the correlations among various network attack techniques. It first vectorizes the attack techniques according to ATT&CK standards, filtering out low-frequency techniques to optimise dimensionality reduction. Parent-child relationships within the ATT&CK classification further facilitate this process. We observe that this strategy can reveal fully connected relationships among high-frequency techniques, while connections are preserved within clusters between high and low-frequency techniques. This structured representation enables the inference of potential attack patterns, achieving a prediction accuracy of 88.11%. We then integrate the identified associations with APT-KG. Experimental validation demonstrates that APT-KG significantly enhances understanding of attack interrelations and improves the efficiency of APT detection and response mechanisms.

Read the paper · More papers on PaperTik