Skip to content

Attack Chain Reconstruction Method Based on LLM Prior-Knowledge Guidance and Heterogeneous Graph Reasoning

Sep 2026 · Electronics · 0 citations · 17 references
Advanced Graph Neural Networks

Abstract

In the face of multi-stage and cross-device complex network attacks, reconstructing the complete attack link from massive heterogeneous security logs is the core problem of security operation. In the existing methods, the traditional graph model lacks a deep understanding of the semantics of alerts, and large language models (LLMs) have the ability of textual reasoning, but have difficulty effectively using the topology between entities, and have difficulty uniformly representing and globally relating multi-source heterogeneous data. Aiming at the above problems, this paper proposes a heterogeneous graph attack chain reconstruction method based on LLM prior-knowledge guidance. Firstly, ontology schemas of six types of core security entities and four types of relationship types are designed for multi-source security logs, and a unified heterogeneous graph representation is constructed by integrating temporal association, spatial association and semantic association. Events scattered in different devices and time windows are correlated into structured views. Secondly, the domain-adaptive fine-tuned LLM is used to encode the deep semantics of the node attribute text, and it is fused with the structural features to make up for the shortcomings of traditional graph neural networks that only rely on shallow statistical features. On this basis, a heterogeneous graph attention mechanism guided by LLM prior knowledge is designed, the attention weight is modulated by the LLM’s semantic score of edge rationality, and candidate attack links are generated by multi-step path reasoning along high-confidence edges. Finally, the logical verification and attack confirmation of the candidate link were carried out step by step with the help of the chain-of-thought ability of LLM, and the confidence was calibrated by temperature scaling. Experiments on DARPA TC and other datasets show that the integrity rate of attack link reconstruction is 86.4%, the coverage rate of attack phase is 82.1%, and the F1 value of attack confirmation is 90.6%, which is significantly better than the methods based on a probabilistic graph model, Heterogeneous Graph Transformer and pure LLM hint engineering. This verifies the effectiveness of the cooperation between semantic understanding and structural reasoning.

Read PDF

Similar papers

#computer vision Open access Jun 2016

Software Development in Startup Companies: The Greenfield Startup Model

The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.

Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al. · 178 citations · ⚡14
#computer vision Open access Oct 2016

Software Startups - A Research Agenda

Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.

M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al. · 157 citations · ⚡17
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#computer vision Review Open access May 2015

A survey study on major technical barriers affecting the decision to adopt cloud services

The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.

Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al. · 111 citations · ⚡8
#computer vision Conference Open access Dec 2013

Affordable and Energy-Efficient Cloud Computing Clusters: The Bolzano Raspberry Pi Cloud Cluster Experiment

The ongoing work building a Raspberry Pi cluster consisting of 300 nodes is presented, with potential use cases being an inexpensive and green test bed for cloud computing research and a robust and mobile data center for operating in adverse environments.

P. Abrahamsson, S. Helmer, Nattakarn Phaphoom et al. · 110 citations · ⚡7
#computer vision Book Open access Mar 2017

On the Unhappiness of Software Developers

The results indicate that software developers are a slightly happy population, but the need for limiting the unhappiness of developers remains, and 219 factors representing causes of unhappiness while developing software are identified.

D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al. · 84 citations · ⚡6

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.