A Critical Review and Paradigm Reconstruction for APT Attack Attribution
Online published: 2026-06-09
Copyright
Against the backdrop of great power strategic competition and digital sovereignty contests, cyber attack attribution has evolved from purely technical tracing into a composite decision problem that integrates forensic analysis, intelligence assessment, strategic-intent judgment, and the allocation of state responsibility under international law. In current Advanced Persistent Threat (APT) attribution paradigms, the micro-level technical paradigm faces challenges such as the failure of feature exclusivity, while the macro-level political paradigm struggles with insufficient evidence transparency. Meanwhile, intelligent paradigms like Knowledge Graphs and Large Language Models (LLMs) encounter bottlenecks in cross-domain integration. A critical review of five major research paradigms was conducted, encompassing technical tracing, political attribution, knowledge graphs, LLMs and agents, and uncertainty quantification. The analysis reveals that the core dilemma in existing attribution research lies in a persistent triple fracture—representational, temporal, and causal—between micro-level technical evidence and macro-level strategic context. Based on this, a Techno-Political Fusion attribution framework is proposed. It advocates for entity extraction and semantic alignment through knowledge learning and analytical algorithms tailored for multi-source heterogeneous data, to populate and validate cross-domain techno-political knowledge graphs, and integrates Dempster-Shafer evidence theory with Bayesian networks for conflict resolution and causal inference, ultimately generating confidence-scored attribution rankings and counterfactual explanations. Future research should construct a cross-domain ontology anchored by four dimensions—technology, organization, politics and events—and to establish a "spatiotemporal-causal" alignment mechanism between micro-level technical indicators and macro-level political contexts. Furthermore, refining the serial reasoning pipeline of "probabilistic inference followed by counterfactual validation" will help transition cyberattack attribution from mere correlation matching toward a causal reasoning system that is auditable, interpretable, and capable of uncertainty quantification.
Lin Xiaoxin , Zhou Yinghai , Lu Hui , Liu Yuan , Song Jing , Du Jing , Tian Zhihong . A Critical Review and Paradigm Reconstruction for APT Attack Attribution[J]. Journal of Cybersecurity, 2026 . DOI: 10.20172/j.issn.2097-3136.260622
表 1 当前网络攻击归因的核心挑战Table 1 The core challenges of current cyber attack attribution |
| 挑战维度 | 具体表现 | 对既有研究的冲击 | 对未来模型的要求 |
| 攻击主体复杂化 | APT组织具备长期潜伏、工具复用、跨境协同能力 | 路径溯源难以指向真实责任主体 | 从机器定位转向组织身份与战略意图推断 |
| 技术证据可操纵 | 假旗、代码复用、基础设施劫持、LotL战术普遍存在 | 静态特征和聚类模型易被误导 | 引入证据可信度评估与对抗鲁棒机制 |
| 政治证据不透明 | 公开归因常缺少完整底层证据链 | 归因结论难以独立复核 | 建立可审计、可追溯的证据链 |
| 跨域表征困难 | 技术变量与政治变量抽象层级差异巨大 | 图嵌入和机器学习模型难以统一表达 | 构建跨域本体与异构图推理框架 |
| 因果机制不足 | 多数模型停留在相关性匹配 | 难以解释“为何此时、为何此目标、为何该主体” | 融合因果图、贝叶斯网络和反事实推理 |
表 2 技术归因与政治归因对比Table 2 Comparison of Technical Attribution and Political Attribution |
| 维度 | 技术归因 | 政治归因 |
| 归因主体 | 安全厂商、学术机构、 CERT | 国家机构、政府背景智库 |
| 证据类型 | 代码、流量、基础设 施、TTPs | 战略意图、地缘事件、 机密情报 |
| 判定逻辑 | 同源性 / 相关性 | 动机—能力—机会 / 战略合理性 |
| 输出粒度 | 攻击组织代号(APTxx) | 主权国家或国家代理人 |
| 可证伪性 | 高(可复核) | 低(情报来源保密) |
| 效力定位 | 取证与防御 | 外交、制裁、威慑 |
| 主要失效模式 | 假旗、工具复用 | 选择性曝光、政治偏倚 |
表 3 主要研究范式的比较分析Table 3 A comparative analysis of the main research paradigms |
| 研究范式 | 代表方法/文献 | 核心优势 | 核心局限 | 适合承担的角色 |
| 流量与路径溯源 | PPM[1]、APM[2]、SPIE[3] | 网络层证据清晰,算法可复核 | 只能定位路径或中间节点, 难以识别真实主体 | 基础取证与路径证据 |
| TTPs与威胁 情报 | 钻石模型[8]、ATT&CK[9]、 痛苦金字塔[10] | 可组织攻击行为模式, 工程落地性强 | 工具复用和假旗行动削 弱特征排他性 | 候选主体生成与行为画像 |
| 政治归因 | Rid & Buchanan[14]、Lin[15]、 Egloff[16] | 能解释国家动机、战略目标和公开归因逻辑 | 证据链透明度不足, 易受政治立场影响 | 宏观先验与动机解释 |
| 知识图谱 | UCO[48]、CyGraph[59]、HIN[61][62] | 可融合异构实体与关系 | 宏观政治本体不足,跨域嵌入困难 | 结构化知识底座 |
| LLM/Agent | CTINexus[54]、CyberSOIE-LLM[70]、PentestGPT[76] | 长文本解析和开放语义 理解能力强 | 幻觉、投毒、长文本衰减和 黑盒推理 | 情报抽取与辅助分析 |
| D-S/贝叶斯推理 | MLDSJ[96]、FAIR-BN[99] | 可表达冲突、不确定性和 后验概率 | 高冲突证据处理与因果图 学习仍不足 | 置信度量化与可审计推理 |
| 1 |
Savage S, Wetherall D, Karlin A, et al. Practical network support for IP traceback[J]. SIGCOMM Computer Communication Review., 2000, 30 (4): 295- 306.
|
| 2 |
Dean D, Thompson M, HU Y C. An algebraic approach to IP traceback[J]. ACM Transactions on Information and System Security (TISSEC), 2002, 5 (2): 119- 137.
|
| 3 |
Snoeren A C, Partridge C, Sanchez L A, et al. Single-packet IP traceback[J]. IEEE/ACM Transactions on Networking, 2002, 10 (6): 721- 734.
|
| 4 |
Sommer R, Paxson V. Exploiting independent state for network intrusion detection[C]// Proceedings of the 21st Annual Computer Security Applications Conference. Washington, DC: IEEE Computer Society, 2005: 413-424.
|
| 5 |
Wang X Y, Chen S P, Jajodia S. Network flow watermarking attack on low-latency anonymous communication systems[C]// Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP '07). Washington, DC: IEEE Computer Society, 2007: 116-130.
|
| 6 |
Gu G F, Porras P, Yegneswaran V, et al. BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation[C]// Proceedings of the 16th USENIX Security Symposium. Berkeley, CA: USENIX Association, 2007: 167-182.
|
| 7 |
MANDIANT. APT1: Exposing one of China’s cyber espionage units[R]. Alexandria, VA: Mandiant, 2013.
|
| 8 |
Caltagirone S, Pendergast A, Betz C. The Diamond Model of Intrusion Analysis[EB/OL]. (2013-07) [2026-04-020]. DOI: 10.13140/RG.2.2.31143.56481.
|
| 9 |
Strom B E, Applebaum A D, Miller D P, et al. MITRE ATT&CK: Design and Philosophy[R]. The MITRE Corporation, 2018.
|
| 10 |
Bianco D. The pyramid of pain[EB/OL]. (2013-03-18)[2026-03-31]. https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html
|
| 11 |
Baram G, Lin H. Navigating uncertainty in cyber conflict: incorporating false flags in the attribution process of offensive cyber operations[J]. Information, Communication & Society, 2025, 28(6): 1-17. DOI: 10.1080/1369118X.2025.2604662.
|
| 12 |
Schölkopf B, Locatello F, Bauer S, et al. Towards causal representation learning[J]. Proceedings of the IEEE, 2021, 109 (5): 612- 634.
|
| 13 |
Simpson E H. The interpretation of interaction in contingency tables[J]. Journal of the Royal Statistical Society: Series B (Methodological), 1951, 13 (2): 238- 241.
|
| 14 |
Rid T, Buchanan B. Attributing cyber attacks[J]. Journal of Strategic Studies, 2015, 38 (1-2): 4- 37.
|
| 15 |
Lin H. Attribution of malicious cyber incidents: From soup to nuts[R]. Hoover Institution, Stanford University, 2016.
|
| 16 |
Egloff F J. Public attribution of cyber intrusions[J]. Journal of Cybersecurity, 2020, 6 (1): tyaa012.
|
| 17 |
Maurer T. Cyber Mercenaries: The State, Hackers, and Power[M]. Cambridge: Cambridge University Press, 2018.
|
| 18 |
李沁东, 陈兴蜀, 唐文佚. 开源威胁情报生产与应用综述[J]. 网络空间安全科学学报, 2023, 1 (1): 59- 80.
Li Q D, Chen X S, Tang W Y. A Survey of Open-Source Threat Intelligence Production and Application[J]. Journal of Cybersecurity, 2023, 1 (1): 59- 80.
|
| 19 |
Bordes A, Usunier N, Garcia-Duran A, et al. Translating embeddings for modeling multi-relational data[C]//Advances in Neural Information Processing Systems (NIPS). 2013: 2787-2795.
|
| 20 |
Wang X, Ji H Y, Shi C, et al. Heterogeneous Graph Attention Network[C]// Proceedings of the 2019 World Wide Web Conference (WWW '19). New York: ACM, 2019.
|
| 21 |
Hutchins E M, Cloppert M J, Amin R M. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains[J]. Leading Issues in Information Warfare & Security Research, 2011, 1 (1): 80- 106.
|
| 22 |
Kostyuk N, Zhukov Y M. Invisible digital front: Can cyber attacks shape battlefield events?[J]. Journal of Conflict Resolution, 2019, 63 (2): 317- 347.
|
| 23 |
Valeriano B, Maness R C. Cyber War versus Cyber Realities: Cyber Conflict in the International System[M]. Oxford: Oxford University Press, 2015.
|
| 24 |
Leetaru K, Schrodt P A. GDELT: Global data on events, location, and tone, 1979-2012[C]//ISA Annual Convention, 2013.
|
| 25 |
Kida M, Olukoya O. Nation-State Threat Actor Attribution Using Fuzzy Hashing[J]. IEEE Access, 2022, 11, 1148- 1165.
|
| 26 |
Rani N, Saha B, Shukla S K. A comprehensive survey of automated Advanced Persistent Threat attribution: Taxonomy, methods, challenges and open research problems[J]. Journal of Information Security and Applications, 2025, 92 (C): 104076.
|
| 27 |
邓钰洋, 朱尧虎. 基于时间感知跨模态对齐的APT狩猎方法[J]. 网络空间安全科学学报, 2026, 4 (2): 29- 49.
Deng Y Y, Zhu Y H. Temporal-aware cross-modal alignment method for APT hunting[J]. Journal of Cybersecurity, 2026, 4 (2): 29- 49.
|
| 28 |
Clarke R A, Knake R K. Cyber War: The Next Threat to National Security and What to Do About It[M]. New York: HarperCollins, 2010.
|
| 29 |
Rid T. Cyber War Will Not Take Place[M]. Oxford: Oxford University Press, 2013.
|
| 30 |
Buchanan B. The Hacker and the State: Cyber Attacks and the New Normal of Geopolitics[M]. Cambridge: Harvard University Press, 2020.
|
| 31 |
Healey J. The spectrum of national responsibility for cyberattacks[J]. Brown Journal of World Affairs, 2011, 18 (1): 57- 70.
|
| 32 |
Schmitt M N. Tallinn Manual on the International Law Applicable to Cyber Warfare[M]. Cambridge: Cambridge University Press, 2013.
|
| 33 |
Schmitt M N. Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations[M]. 2nd ed. Cambridge: Cambridge University Press, 2017.
|
| 34 |
沈逸. 全球网络空间治理原则之争与中国的战略选择[J]. 外交评论(外交学院学报), 2015, 32 (2): 65- 79.
Shen Y. The debate on the principles of global cyberspace governance and China's strategic choice[J]. Foreign Affairs Review, 2015, 32 (2): 65- 79.
|
| 35 |
沈逸. 为全球网络空间治理良性变革贡献中国方案[J]. 人民论坛·学术前沿, 2020 (2): 36- 42.
Shen Y. Contributing the China Program to the Virtuous Transformation of Global Cyberspace Governance[J]. People's Tribune·Academic Frontier, 2020 (2): 36- 42.
|
| 36 |
鲁传颖. 网络空间安全困境及治理机制构建[J]. 现代国际关系, 2018 (11): 49- 55+66+68.
Lu C Y. The security dilemma in cyberspace and the construction of governance mechanisms[J]. Contemporary International Relations, 2018 (11): 49- 55+66+68.
|
| 37 |
胡冯彬, 沈逸. 数字时代的新地缘政治博弈与冲突协调[M]. 北京: 时事出版社, 2024.
Hu F B, Shen Y. New Geopolitical Game and Conflict Coordination in the Digital Age[M]. Beijing: Current Affairs Press, 2024. (in Chinese)
|
| 38 |
Lindsay J R. The impact of China on cybersecurity: Fiction and friction[J]. International Security, 2015, 39 (3): 7- 47.
|
| 39 |
CROWDSTRIKE. 2023 Global Threat Report[R]. Austin: CrowdStrike, 2023.
|
| 40 |
MANDIANT. M-Trends 2023: Special Report[R]. Milpitas: Mandiant, 2023.
|
| 41 |
国家计算机病毒应急处理中心, 360公司. 西北工业大学遭美国NSA网络攻击事件调查报告(之一)[R/OL]. (2022-09-05) [2026-04-05]. https://www.cverc.org.cn/head/zhaiyao/news20220905-NPU.htm.
National Computer Virus Emergency Response Center, 360. Investigation report on the cyber attack against Northwestern Polytechnical University by the U. S. NSA (Part 1)[R/OL]. (2022-09-05)[2026-04-05]. https://www.cverc.org.cn/head/zhaiyao/news20220905-NPU.htm. (in Chinese)
|
| 42 |
Harknett R J, Smeets M. Cyber campaigns and strategic outcomes[J]. Journal of Strategic Studies, 2022, 45 (4): 534- 567.
|
| 43 |
Farrell H, Newman A. Weaponized Interdependence: How Global Economic Networks Shape Coercion and Surveillance[J]. International Security, 2019, 44 (1): 42- 79.
|
| 44 |
360数字安全集团. 2025全球高级持续性威胁(APT)研究报告[R]. 2026.
Digital Security Group. 2025 Global Advanced Persistent Threat (APT) Research Report[R]. 2026. (in Chinese)
|
| 45 |
陈慧慧, 胡光俊. 美国构建“中国网络威胁”叙事的认知塑造机制研究与事件分析[J]. 中国信息安全, 2026 (3): 51- 57.
Chen H H, Hu G J. Research on the cognitive shaping mechanism and event analysis of the U. S. constructing the "China cyber threat" narrative[J]. China Information Security, 2026 (3): 51- 57.
|
| 46 |
徐增林, 盛泳潘, 贺丽荣, 等. 知识图谱技术综述[J]. 电子科技大学学报, 2016 (4): 589- 606.
Xu Z L, Sheng Y P, He L R, et al. A survey of knowledge graph technology[J]. Journal of University of Electronic Science and Technology of China, 2016 (4): 589- 606.
|
| 47 |
刘峤, 李杨, 段宏, 等. 知识图谱构建技术综述[J]. 计算机研究与发展, 2016, 53 (3): 582- 600.
Liu Q, Li Y, Duan H, et al. A survey of knowledge graph construction techniques[J]. Journal of Computer Research and Development, 2016, 53 (3): 582- 600.
|
| 48 |
Syed Z, Padia A, Finin T, et al. UCO: A Unified Cybersecurity Ontology[C]. AAAI Workshop, 2016.
|
| 49 |
Mavroeidis V, Bromander S. Cyber Threat Intelligence Model: An Evaluation of Taxonomies, Sharing Standards, and Ontologies within Cyber Threat Intelligence[C]// 2017 European Intelligence and Security Informatics Conference (EISIC). Athens, Greece: IEEE, 2017: 91-98.
|
| 50 |
Liao X J, Yuan K, Wang X F, et al. Acing the IOC game: Toward automatic discovery and analysis of CTI[C]. ACM CCS, 2016.
|
| 51 |
Gao P, Shao F, Liu X Y, et al. A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence[C]// 2021 IEEE 37th International Conference on Data Engineering (ICDE). Chania, Greece: IEEE, 2021: 2381-2384.
|
| 52 |
Zhao J, Yan Q B, Li J X, et al. TIMiner: Automatically Extracting and Analyzing Categorized Cyber Threat Intelligence from Social Data[J]. Computers & Security, 2020.
|
| 53 |
许智双, 张昆, 范俊超, 等. 基于本体的网络安全知识图谱构建方法[J]. 信息网络安全, 2025, 25 (3): 451- 466.
Xu Z S, Zhang K, Fan J C, et al. A method for constructing a cybersecurity knowledge graph based on ontology[J]. Information Network Security, 2025, 25 (3): 451- 466.
|
| 54 |
Cheng Y T, Bajaber O, Tsegais A S, et al. CTINEXUS: Automatic Cyber Threat Intelligence Knowledge Graph Construction Using Large Language Models[C]// Proceedings of the 2025 IEEE European Symposium on Security and Privacy (EuroS&P). Piscataway: IEEE, 2025.
|
| 55 |
Husari G, Al-Shaer E, Rahman M, et al. TTPDrill: Automatic and accurate extraction of threat actions from unstructured text of CTI sources[C]//Proceedings of the 33rd Annual Computer Security Applications Conference (ACSAC). 2017: 103-115.
|
| 56 |
Piplai A, Mittal S, Joshi A, et al. Creating Cybersecurity Knowledge Graphs From Malware After Action Reports[J]. IEEE Access, 2020, 8, 211691- 211703.
|
| 57 |
Ren Y T, Xiao Y J, Zhou Y H, et al. CSKG4APT: A cybersecurity knowledge graph for advanced persistent threat organization attribution[J]. IEEE Transactions on Knowledge and Data Engineering, 2022, 35 (6): 5695- 5709.
|
| 58 |
Ma B Q, Zhou Y H, Wu S, et al. APT-KG2QA: An intelligent fine-tuning strategy for large language models utilizing the APT knowledge graph[J]. IEEE Internet of Things Journal, 2025, 12 (18): 38493- 38508.
|
| 59 |
Noel S, Harley E, Tam K H, et al. CyGraph: Graph-based analytics and visualization for cybersecurity[M] // GUDIVADA V N, RAGHAVAN V V, GOVINDARAJU V, et al. , eds. Handbook of statistics. Vol. 35. Amsterdam: Elsevier, 2016: 117-167. DOI: 10.1016/bs.host.2016.07.001.
|
| 60 |
Bilot T, Madhoun N E, Agha K A, et al. Graph neural networks for intrusion detection: a survey[J]. IEEE Access, 2023, 11, 49114- 49139.
|
| 61 |
Sun Y Z, Han J W. Mining heterogeneous information networks: A structural analysis approach[J]. ACM SIGKDD, 2013, 14 (2): 20- 28.
|
| 62 |
Hou S F, Ye Y F, Song Y Q, et al. HinDroid: An intelligent android malware detection system based on structured heterogeneous information network[C]// Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Association for Computing Machinery, 2017, p. 1507-1516.
|
| 63 |
Abu-salih B. Domain-specific Knowledge Graphs: A survey[J]. Journal of Network and Computer Applications, 2021, 185, 103076.
|
| 64 |
He K M, Zhang X Y, Ren S Q, et al. Deep residual learning for image recognition[C]// 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE, 2016: 770-778.
|
| 65 |
Vaswani A, Shazeer N, Parmar N, et al. Attention is all you need[C]// Proceedings of the 31st International Conference on Neural Information Processing Systems. Red Hook, NY: Curran Associates Inc. , 2017: 6000-6010.
|
| 66 |
Mnih V, Kavukcuoglu K, Silver D, et al. Human-level control through deep reinforcement learning[J]. Nature, 2015, 518 (7540): 529- 533.
|
| 67 |
Gholami Y. Large Language Models (LLMs) for Cybersecurity: A Systematic Review[J]. World Journal of Advanced Engineering Technology and Sciences, 2024, 13 (01): 057- 069.
|
| 68 |
Chen Y R, Cui M J, Wang D, et al. A Survey of Large Language Models for Cyber Threat Detection[J]. Computers & Security, 2024, 145, 104016.
|
| 69 |
Jaffal N O, Alkhanafseh M, Mohaisen D. Large Language Models in Cybersecurity: A Survey of Applications, Vulnerabilities, and Defense Techniques[J]. AI, 2025, 6 (9): 216.
|
| 70 |
Liu X Z, Ding Z Y. CyberSOIE-LLM: Cybersecurity Semi-Open Information Extraction with Large Language Models[C]//2025 IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). Guiyang: IEEE, 2025: 1435-1442.
|
| 71 |
马冰琦, 周盈海, 王梓宇, 等. 一种基于大语言模型的威胁情报信息抽取方法[J]. 网络空间安全科学学报, 2024, 2 (2): 36- 46.
Ma B Q, Zhou Y H, Wang Z Y, et al. A LLMs-based method for threat intelligence information extraction[J]. Journal of Cybersecurity, 2024, 2 (2): 36- 46.
|
| 72 |
SENTINELONE LABS. From Narrative to Knowledge Graph: LLM-Driven Information Extraction in Cyber Threat Intelligence [EB/OL]. [2026-04-19]. https://www.sentinelone.com/labs/from-narrative-to-knowledge-graph-llm-driven-information-extraction-in-cyber-threat-intelligence/.
|
| 73 |
Hu Y L, Zou F T, Han J J, et al. LLM-TIKG: Threat intelligence knowledge graph construction utilizing large language model[J]. Computers & Security, 2024, 145, 103999.
|
| 74 |
Wei J, Wang X Z, Schuurmans D, et al. Chain-of-Thought Prompting Elicits Reasoning in Large Language Models[C]// Proceedings of the 36th International Conference on Neural Information Processing Systems. Red Hook, NY: Curran Associates Inc. , 2022: 24824-24837.
|
| 75 |
Yao S Y, Zhao J, Yu D, et al. ReAct: Synergizing reasoning and acting in language models[C]//International Conference on Learning Representations (ICLR). 2023.
|
| 76 |
Deng G L, Liu Y, Mayoral-Vilches V, et al. PentestGPT: An LLM-empowered automated penetration testing tool[C]// Proceedings of the 33rd USENIX Conference on Security Symposium. Philadelphia: USENIX Association, 2024: 847-864.
|
| 77 |
Wu X Y, Tian Y Z, Chen Y W, et al. CurriculumPT: LLM-Based multi-agent autonomous penetration testing with curriculum-guided task scheduling[J]. Applied Sciences, 2025, 15 (16): 9096.
|
| 78 |
Liu N F, Lin K, Hewitt J, et al. Lost in the middle: How language models use long contexts[J]. Transactions of the Association for Computational Linguistics (TACL), 2024, 12, 157- 173.
|
| 79 |
Ji Z W, Lee N, Frieske R, et al. Survey of hallucination in natural language generation[J]. ACM Computing Surveys, 2023, 55 (12): 1- 38.
|
| 80 |
Alam M T, Bhusal D, Nguyen L, et al. CTIBench: A benchmark for evaluating LLMs in cyber threat intelligence[C] // Advances in Neural Information Processing Systems. Vol. 37. [S. l. ]: Curran Associates, Inc. , 2024: 50805-50825.
|
| 81 |
陈晨, 李云春, 夏铭远, 等. LLM驱动的威胁情报知识图谱自动构建方法[J]. 网络空间安全科学学报, 2025, 3 (6): 112- 122.
Chen C, Li Y C, Xia M Y, et al. Automated threat intelligence knowledge graph construction using LLM[J]. Journal of Cybersecurity, 2025, 3 (6): 112- 122.
|
| 82 |
Liu B, Zhao Y J, Xu G A, et al. LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet? [EB/OL]. (2025-10-16) [2026-04-19]. https://arxiv.org/abs/2510.14700.
|
| 83 |
Gandhi P A, Shukla A, Tayouri D, et al. ATAG: AI-Agent Application Threat Assessment with Attack Graphs[EB/OL]. (2025-06-03) [2026-04-19]. https://arxiv.org/abs/2506.02859.
|
| 84 |
Srinivas S, Kirk B, Zendejas J, et al. AI-Augmented SOC: A Survey of LLMs and Agents for Security Automation[J]. Journal of Cybersecurity and Privacy, 2025, 5 (4): 95.
|
| 85 |
Safavi S, Abdulnabi M, Rana M E, et al. From black box to trustworthy AI: a secure framework for explainable cybersecurity decision-making[C]//Proceedings of 2025 International Conference on Advancements in Smart, Secure and Intelligent Computing (ASSIC). Bhubaneswar, India: IEEE, 2025: 1-4.
|
| 86 |
Zhao C S, Tan Z, Ma P C, et al. Is chain-of-thought reasoning of LLMs a mirage? A data distribution lens[C]//Proceedings of the First Workshop on Foundations of Reasoning in Language Models (FoRLM 2025). 2025.
|
| 87 |
Clairoux-Trepanier V, Beauchamp I M, Ruellan E, et al. The Use of Large Language Models (LLM) for Cyber Threat Intelligence (CTI) in Cybercrime Forums[EB/OL]. (2024-10-01) [2026-04-19]. https://arxiv.org/abs/2408.03354.
|
| 88 |
Shafee S, Bessani A, Ferreira P M. False Alarms, Real Damage: Adversarial Attacks Using LLM-based Models on Text-based Cyber Threat Intelligence Systems[J]. Future Generation Computer Systems, 2026, 108603. DOI: https://doi.org/10.1016/j.future.2026.108603.
|
| 89 |
Meng Y Q, Tang L X, Yu F Y, et al. Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence[EB/OL]. (2025-09-30)[2026-04-19]. https://arxiv.org/abs/2509.23573.
|
| 90 |
Brodt O, Feldman E, Schneier B, et al. The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism[EB/OL]. (2026-01-01)[2026-04-19]. https://arxiv.org/abs/2601.09625.
|
| 91 |
Luo Z X, Fan Y H, Lin H Y, et al. Auditing Cascading Risks in Multi-Agent Systems via Semantic-Geometric Co-evolution[EB/OL]. (2026-03-04)[2026-04-19]. https://arxiv.org/abs/2603.13325.
|
| 92 |
Skopik F, Pahi T. Under false flag: using technical artifacts for cyber attack attribution[J]. Cybersecur, 2020, 3 (1): 8.
|
| 93 |
Gerwen S V, Constantino J, Roothaert R, et al. To know what you do not know: Challenges for explainable AI for security and threat intelligence[M]//Sipola T, Alatalo J, Wolfmayr M, et al. (Eds.). Artificial Intelligence for Security. Cham: Springer, 2024: 55-83. DOI: 10.1007/978-3-031-57452-8_4.
|
| 94 |
Xiao N, Lang B, Wang T, et al. APT-MMF: An advanced persistent threat actor attribution method based on multimodal and multilevel feature fusion[J]. Computers & Security, 2024, 144, 103960.
|
| 95 |
Wagner T D, Mahbu B K, Palomar E, et al. Cyber threat intelligence sharing: Survey and research directions[J]. Computers & Security, 2019, 87, 101589.
|
| 96 |
Duan L X, Wen M, Xiong Y. MLDSJ: a multi-level feature joint attribution method for APT group based on threat intelligence[J]. EURASIP Journal on Information Security, 2026, 2026, 2.
|
| 97 |
Qian F, Lu G S, Li L C, et al. Construction of a Network Security Compliance Check and Situational Correlation Model Based on Multi-Source Data Fusion[C]//2025 10th International Conference on Cyber Security and Information Engineering (ICCSIE). Xining, China: IEEE, 2025: 198-205.
|
| 98 |
Chockalingam S, Pieters W, Teixeira A, et al. Bayesian Network Models in Cyber Security: A Systematic Review[C]// Lipmaa H, Mitrokotsa A, Matulevicius R, eds. Secure IT Systems: NordSec 2017. Lecture Notes in Computer Science. Cham: Springer, 2017, 10674: 105-122.
|
| 99 |
Wang J L, Neil M, Fenton N. A Bayesian network approach for cybersecurity risk assessment implementing and extending the FAIR model[J]. Computers & Security, 2020, 89 (C): 101659.
|
| 100 |
Wei X Y, Dong Y D. A hybrid approach combining Bayesian networks and logistic regression for enhancing risk assessment[J]. Scientific Reports, 2025, 15, 26802.
|
/
| 〈 |
|
〉 |