电子学报2026,Vol.54Issue(1):1-18,18.DOI:10.12263/DZXB.20250681
攻击技战术双层关联建模的个性化风险评估方法
A Personalized Risk Assessment Approach for Two-Layer Association Modeling of Attack Techniques and Tactics
摘要
Abstract
Guided by the MITRE ATT&CK framework,modeling and assessing cybersecurity risks by modeling at-tackers'tactical objectives and technical methods through attack graphs have become one of the key approaches to counter-ing complex multi-step attack threats.However,as attack scenarios and attack chains grow increasingly intricate,existing ATT&CK-based attack path modeling and risk assessment methods exhibit certain limitations.On the one hand,current at-tack path modeling processes only consider direct transition relationships between attack techniques within the ATT&CK framework,overlooking tactical-level attack semantics and weakening the ability to impose high-level semantic constraints on complex multi-stage attack paths.On the other hand,attack graph-based risk quantification methods relying on generic vulnerability characteristics overlook differences in organizational focus on critical assets,resulting in assessment outcomes that lack personalized asset adaptation.To address these challenges,this paper proposes a personalized risk assessment meth-od based on dual-layer association modeling of attack techniques and tactics.First,a dual-layer association model is con-structed to capture potential relationships between techniques and tactics.Combined with the Viterbi algorithm,this model infers the evolution paths of attack tactics,introducing tactical-level stage constraints during path inference.Subsequently,a customized threat quantification model is developed by integrating attack behavior attributes with asset-specific characteris-tics.Through a forward algorithm,state transition probabilities are coupled with threat quantification metrics to achieve ho-listic network security risk assessment.Experimental results demonstrate that the proposed method outperforms existing mainstream assessment models in both path modeling and risk evaluation capabilities in real-world network environments.Compared with competing approaches,the proposed method achieves an average improvement of 48.95%in comprehensive risk assessment accuracy,validating its effectiveness and practical value in complex attack scenarios.关键词
网络安全/逻辑攻击图/风险评估/隐马尔可夫模型/ATT&CK框架/风险路径识别Key words
cybersecurity/logical attack diagram/risk assessment/hidden Markov model/ATT&CK framework/risk path identification分类
信息技术与安全科学引用本文复制引用
仇晶,农李晨,孙一飞,操晓春,陈玺名,张睿智..攻击技战术双层关联建模的个性化风险评估方法[J].电子学报,2026,54(1):1-18,18.基金项目
国家自然科学基金(No.U24A20336) (No.U24A20336)
国家科技重大专项(No.2022ZD0119602) (No.2022ZD0119602)
广州市科技计划项(No.2024A03J0399) (No.2024A03J0399)
鹏程实验室重大重点项目(No.PCL2024A05) National Natural Science Foundation of China(No.U24A20336) (No.PCL2024A05)
National Science and Tech-nology Major Project of China(No.2022ZD0119602) (No.2022ZD0119602)
Guangzhou Science and Technology Program(No.2024A03J0399) (No.2024A03J0399)
Major Key Project of Pengcheng Laboratory(No.PCL2024A05) (No.PCL2024A05)