信息网络安全 ›› 2026, Vol. 26 ›› Issue (6): 833-853.doi: 10.3969/j.issn.1671-1122.2026.06.001

• 学术研究 • 上一篇    下一篇

高级持续性威胁检测与溯源研究进展

孙钰1,2(), 张轩瑞1,2, 刘新宇1,2   

  1. 1 北京航空航天大学网络空间安全学院北京 100191
    2 空天地一体化综合业务网全国重点实验室西安 710071
  • 收稿日期:2026-03-03 出版日期:2026-06-10 发布日期:2026-07-27
  • 通讯作者: 孙钰 E-mail:sunyv@buaa.edu.cn
  • 作者简介:孙钰(1985—),男,山东,副教授,博士,主要研究方向为智能系统安全|张轩瑞(2004—),男,北京,本科,主要研究方向为智能系统安全|刘新宇(1999—),男,江苏,博士研究生,主要研究方向为人工智能安全
  • 基金资助:
    国家自然科学基金(62472015);空天地一体化综合业务网全国重点实验室开放课题(ISN26-13)

Advances in Advanced Persistent Threat Detection and Provenance Research

SUN Yu1,2(), ZHANG Xuanrui1,2, LIU Xinyu1,2   

  1. 1 School of Cyber Science and Technology, Beihang University, Beijing 100191, China
    2 State Key Laboratory of Integrated Services Networks, Xi’an 710071, China
  • Received:2026-03-03 Online:2026-06-10 Published:2026-07-27
  • Contact: SUN Yu E-mail:sunyv@buaa.edu.cn

摘要:

近年来,高级持续性威胁(APT)攻击呈现爆发式增长,对政府机构和关键基础设施安全构成严峻挑战。基于溯源图的入侵检测系统(PIDS)通过捕获和分析系统层面的依赖关系,成为检测复杂、隐蔽的APT攻击的重要手段。首先,文章阐述了支撑PIDS研究的各类测试基准,并分析了其在规模、复杂性、攻击覆盖和标注质量等方面存在的局限。进一步以溯源图为基础,对现有的APT检测与攻击溯源方法进行分类,揭示了从早期规则匹配到机器学习,再到当前基于大语言模型(LLM)方法的技术演进路径,并总结了各类方法的优势与不足。文章对基于LLM的APT检测与溯源的范式进行了归纳,并逐步厘清了该领域面临的关键挑战。最后,对未来研究方向进行了展望。

关键词: 高级持续性威胁, 溯源图, 入侵检测系统, 大语言模型

Abstract:

In recent years, advanced persistent threat (APT) attacks have experienced explosive growth, posing severe challenges to government agencies and critical infrastructure. Provenance-based intrusion detection systems (PIDS), which capture and analyze system-level dependency relationships, provide a key means for detecting complex and stealthy APT attacks. This paper first analyzed various benchmark datasets supporting PIDS research, highlighting their limitations in scale, complexity, attack coverage, and annotation quality. Furthermore, based on provenance graphs, it classified existing APT detection and investigation methods, revealing the technological evolution from early rule-based matching to machine learning and current approaches utilizing Large Language Model (LLM). The advantages and disadvantages of each category were summarized. This work presented systematic review of the paradigm for LLM-based APT detection and investigation and clarified the key challenges faced in this field. Finally, it outlined prospects for future research directions.

Key words: advanced persistent threat, provenance graph, intrusion detection system, large language model

中图分类号: