| 大语言模型驱动的威胁情报知识图谱构建方法 |
| An LLM‑driven knowledge graph construction method for threat intelligence |
| |
| DOI: |
| 中文关键词: 大语言模型;威胁情报;自然语言处理;知识图谱 |
| 英文关键词:large language model (LLM); threat intelligence; natural language processing; knowledge graph |
| 基金项目:国家自然科学基金(62572255)和江苏省前沿技术研发计划(BF2024071)资助项目 |
| 作者 | 单位 | | 陈霄 | 1. 南京邮电大学 计算机学院,江苏 南京 210023
2. 南京邮电大学 江苏省物联网智能感知与计算重点实验室,江苏 南京 210023 | | 沙乐天 | 1. 南京邮电大学 计算机学院,江苏 南京 210023
2. 南京邮电大学 江苏省物联网智能感知与计算重点实验室,江苏 南京 210023 | | 董建阔 | 1. 南京邮电大学 计算机学院,江苏 南京 210023
2. 南京邮电大学 江苏省物联网智能感知与计算重点实验室,江苏 南京 210023 | | 肖甫 | 1. 南京邮电大学 计算机学院,江苏 南京 210023
2. 南京邮电大学 江苏省物联网智能感知与计算重点实验室,江苏 南京 210023 |
|
| 摘要点击次数: 184 |
| 全文下载次数: 93 |
| 中文摘要: |
| 随着网络威胁的日益复杂化,传统依赖人工分析和规则匹配的安全防护手段已难以应对海
量异构的威胁情报。针对网络威胁情报来源分散、格式异构,导致内部的复杂威胁关系和关键知
识难以被高效整合与深度关联分析的问题,提出一种大语言模型(Large Language Model, LLM)驱
动的威胁情报知识图谱构建方法。首先,通过多源数据接入与统一语义建模,将攻击者、目标环
境、攻击方式等要素抽象为标准化多维属性体系;然后,基于偏差反馈的动态提示词优化框架,驱
动 LLM实现多轮自适应实体关系抽取;最后,通过领域自适应的实体指纹相似度融合算法与图分
片管理机制,在本地图数据库中构建高效可扩展的威胁情报知识图谱。实验结果表明,所构建图
谱的实体覆盖率达到 94.2%,图连通率达到 86.3%,优于当前主流技术,为自动化威胁分析提供高
连通性、低冗余的动态知识支撑。 |
| 英文摘要: |
| With the increasing sophistication of cyber threats, traditional security measures that rely on
manual analysis and rule-matching struggle to cope with vast, heterogeneous threat intelligence. To address the challenges posed by fragmented sources and disparate formats that hinder efficient integration
and deep relational analysis of complex threat knowledge, this paper proposes a large language model
(LLM)-driven method to construct a threat intelligence knowledge graph. First, it establishes a standardized multi-dimensional attribute system by abstracting elements such as attackers, target environments,
and attack methods through multi-source data ingestion and unified semantic modeling. Second, an LLM
is employed within a prompt optimization framework driven by deviation feedback to perform multi-turn
adaptive entity and relation extraction. Finally, it builds an efficient and scalable threat intelligence
knowledge graph in a local graph database by utilizing a domain-adaptive entity fingerprint similarity fusion algorithm and a graph sharding management mechanism. Experimental results demonstrate that the
constructed knowledge graph achieves an entity coverage of 94.2% and a graph connectivity of 86.3%,
outperforming current mainstream techniques, thereby providing highly connected and low-redundancy
dynamic knowledge support for automated threat analysis. |
| 查看全文 查看/发表评论 附件 |