Netinfo Security ›› 2026, Vol. 26 ›› Issue (6): 833-853.doi: 10.3969/j.issn.1671-1122.2026.06.001

Previous Articles     Next Articles

Advances in Advanced Persistent Threat Detection and Provenance Research

SUN Yu1,2(), ZHANG Xuanrui1,2, LIU Xinyu1,2   

  1. 1 School of Cyber Science and Technology, Beihang University, Beijing 100191, China
    2 State Key Laboratory of Integrated Services Networks, Xi’an 710071, China
  • Received:2026-03-03 Online:2026-06-10 Published:2026-07-27
  • Contact: SUN Yu E-mail:sunyv@buaa.edu.cn

Abstract:

In recent years, advanced persistent threat (APT) attacks have experienced explosive growth, posing severe challenges to government agencies and critical infrastructure. Provenance-based intrusion detection systems (PIDS), which capture and analyze system-level dependency relationships, provide a key means for detecting complex and stealthy APT attacks. This paper first analyzed various benchmark datasets supporting PIDS research, highlighting their limitations in scale, complexity, attack coverage, and annotation quality. Furthermore, based on provenance graphs, it classified existing APT detection and investigation methods, revealing the technological evolution from early rule-based matching to machine learning and current approaches utilizing Large Language Model (LLM). The advantages and disadvantages of each category were summarized. This work presented systematic review of the paradigm for LLM-based APT detection and investigation and clarified the key challenges faced in this field. Finally, it outlined prospects for future research directions.

Key words: advanced persistent threat, provenance graph, intrusion detection system, large language model

CLC Number: