Aiming at the problem that existing cybersecurity event detection methods lack effective utilization of multi-level semantic information and dependent syntactic information, and rely on triggers for event detection, thus affecting the detection performance, this paper proposes a cybersecurity event detection method fusing multi-level semantic and dependent syntax information. First, incorporating a BiLSTM model with the SecureBERT pre-training model to capture domain-specific semantic information and contextual information in cybersecurity text. Through an event description-aware attention mechanism, the relationship between the sentence to be detected and the event description is captured, focusing on the parts of the sentence more relevant to the event and obtaining multi-level semantic feature vectors. Then, the position-aware function is introduced into the graph convolutional network, and the dependency syntactic relationship is deeply analyzed, and the dependency syntactic feature vector is obtained. Finally, the features are fused through the gating mechanism and the fused feature is input into the cybersecurity event detector for binary classification, detecting and recognizing cybersecurity events in the text. The experimental results show that compared with the existing methods, the F1 scores of this paper’s method on CASIE and CySecED datasets are improved by 2.0%~7.9% and 2.8%~26.6% respectively, with good detection results.
事件检测(Event detection,ED)是自然语言处理(Natural language processing, NLP)领域中信息抽取任务的关键组成部分,主要任务是从文本中识别预定义的事件类型[11]。网络安全事件检测旨在判断给定的文本中是否存在预定义的网络安全事件类型,使安全分析人员能够及时地了解网络威胁的发生,从而提高安全分析的效率。事件检测任务中,通过标记名为事件触发词的单词或短语表示特定事件的发生,事件触发词通常为动词或者动名词[12]。传统的事件检测方法依赖于识别触发词并将其正确分类为预定义的事件类型,以识别文本中的事件类型[13-15]。因此,事件检测的效果在很大程度上受到触发词标注质量的影响,而触发词标注过程通常耗费大量人力物力,基于触发词的事件检测方法难以适用于需要大量专家标注工作的网络安全领域。
(2)提出了一种多层次语义特征提取网络,该网络通过SecureBERT预训练模型对句子内容进行编码,有效获取网络安全专业领域的语义信息,在此基础上利用双向长短期记忆(Bidirection long and short-term memory,BiLSTM)网络进一步提取文本的上下文信息,并通过事件描述感知注意力机制对事件描述的向量表示和经过BiLSTM获取的语义特征表示进行计算,从而获取多层次语义特征表示,增强对网络安全文本复杂语义信息的分析能力。
Satyapanich等[10]提出一个名为网络攻击感知与信息提取(CyberAttack sensing and information extraction,CASIE)的系统提取网络安全事件,他们还标记了一个数据集,其中包括5种预定义的事件类型。CASIE中的CyberLSTM方法利用带有注意力层的BiLSTM网络提取触发词信息进行事件检测,但触发词标记质量不佳的情况下将导致事件检测效果下降,并且没有考虑依存句法信息。Trong等[18]为网络安全事件检测引入一个新的数据集,包含30种重要的网络安全事件类型。他们在该数据集上对多个事件检测方法进行评估,结果表明利用更加丰富的特征,如专业领域语义信息、文档级信息以及依存句法信息等,可以有效提高事件检测效果。Yagcioglu等[19]提出一个通过卷积神经网络和BiLSTM的模型对噪声短文进行分类的方法,从而检测Twitter上的网络安全事件,该方法的文本特征提取方式未考虑依存句法信息导致检测性能不佳。Wang等[20]提出多阶边感知图卷积网络提取高阶依存句法关系,但是仅使用BERT模型的文本编码方式未能有效获取网络安全专业领域的语义信息。Liu[21]对预训练模型在网络安全领域中的研究工作进行综述,表明网络安全专业领域预训练模型的出现,可以有效提高文本分析等下游任务模型的语义分析能力。Wang等[22]通过拼接事件描述信息并对句子建模实现无触发词网络安全事件检测,但是该方法仅通过图卷积网络生成句子的整体表示,未能有效融合网络安全专业领域语义信息和上下文信息,从而影响事件检测效果。Tang等[23]提出一种基于对比学习的网络安全事件检测方法,通过测量候选实例与已有实例之间的语义相似性实现无触发词网络安全事件检测。汤萌萌等[24]通过提示问答并结合标签词对数据进行增强实现小样本事件检测,提示问题的设计质量对模型性能有显著影响。
为了进一步观察模型的性能,评估事件描述感知注意力的效果,对CySecED数据集中的“Any malicious site can potentially make a victim’s web browser connect to a My Cloud device on the network and compromise it”语句进行注意力分数可视化实例分析,这句话在数据集中标注为“ATTACK.Web Compromise”事件类型,事件描述感知注意力学习到的注意力分数的两种情况如图7所示。
YangXiu-zhang, PengGuo-jun, LiZi-chuan, et al. Research on entity recognition and alignment of APT attack based on Bert and BiLSTM-CRF[J]. Journal on Communications, 2022, 43(6): 58-70.
[7]
WangX, LiuJ. A novel feature integration and entity boundary detection for named entity recognition in cybersecurity[J]. Knowledge-Based Systems, 2023, 260: No. 110114.
[8]
WangG, LiuP, HuangJ, et al. KnowCTI: knowledge-based cyber threat intelligence entity and relation extraction[J]. Computers & Security, 2024, 141:No. 103824.
[9]
JoH, LeeY, ShinS. Vulcan: automatic extraction and analysis of cyber threat intelligence from unstructured text[J]. Computers & Security, 2022, 120:No.102763.
ShiHui-yang, WeiJing-xuan, CaiXing-ye, et al. Research on threat intelligence extraction and knowledge graph construction technology[J]. Journal of Xidian University, 2023, 50(4): 65-75.
[12]
LiZ, ZengJ, ChenY, et al. AttacKG: constructing technique knowledge graph from cyber threat intelligence reports[C]∥European Symposium on Research in Computer Security,Copenhagen, Denmark, 2022: 589-609.
[13]
SatyapanichT, FerraroF, FininT. Casie: extracting cybersecurity event information from text[C]∥Proceedings of the AAAI Conference on Artificial Intelligence, New York,USA,2020: 8749-8757.
[14]
LiQ, LiJ, ShengJ, et al. A survey on deep learning event extraction: approaches and applications[J]. IEEE Transactions on Neural Networks and Learning Systems, 2022, 35(5): 6301-6321.
RenYong-gong, LinYu-zhu, TangYu-jie, et al. A biomedical event trigger identification method based on hybrid neural network and attention mechanism[J]. Acta Electronica Sinica, 2024, 52(9): 3206-3216.
XiaoMeng-nan, HeRui-fang, MaJin-song. Event detection based on hierarchical latent semantic-driven network[J]. Journal of Computer Research and Development, 2024, 61(1): 184-195.
LiuLiu, DingKun, LiuShan-shan, et al. Event detection method as machine reading comprehension[J]. Journal of Jilin University (Engineering and Technology Edition), 2024, 54(2): 533-539.
[23]
LiuS, LiY, ZhangF, et al. Event detection without triggers[C]∥Proceedings of the Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Minneapolis, USA, 2019: 735-744.
ChengYong, MaoYing-chi, WanXu, et al. Chinese event detection without triggers based on dual attention[J]. Computer Science, 2023, 50(1): 276-284.
[26]
TrongH M D, LeD T, VeysehA P B, et al. Introducing a new dataset for event detection in cybersecurity texts[C]∥Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP), Online, 2020: 5381-5390.
[27]
YagciogluS, SeyfiogluM S, CitamakB, et al. Detecting cybersecurity events from noisy short text[C]∥Proceedings of the Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies,Minneapolis, USA, 2019: 1366-1372.
[28]
WangJ, WangK, YaoY, et al. Event detection with multi-order edge-aware graph convolution networks[J]. Data & Knowledge Engineering, 2023, 143: No. 102109.
[29]
LiuZ. A review of advancements and applications of pre-trained language models in cybersecurity[C]∥The 12th International Symposium on Digital Forensics and Security(ISDFS), San Antonio,USA, 2024: 1-10.
[30]
WangG, LiuP, HuangJ, et al. CSEDesc: cyberSecurity event detection with event description[C]∥International Conference on Artificial Neural Networks, Heraklion, Greece, 2023: 26-38.
[31]
TangM, GuoY, BaiQ, et al. Trigger-free cybersecurity event detection based on contrastive learning[J]. The Journal of Supercomputing, 2023, 79(18): 20984-21007.
TangMeng-meng, GuoYuan-bo, ZhangHan, et al. Few-shot network security event detection method by data augmentation with prompting question answering[J]. Journal on Communications, 2024,45(8):62-74.
[34]
ManningC D, SurdeanuM, BauerJ, et al. The Stanford CoreNLP natural language processing toolkit[C]∥Proceedings of 52nd Annual Meeting of the Association for Computational Linguistics: System Demonstrations, Baltimore, USA, 2014: 55-60.
[35]
AghaeiE, NiuX, ShadidW, et al. Securebert: a domain-specific language model for cybersecurity[C]∥International Conference on Security and Privacy in Communication Systems,Dalian,China, 2022: 39-56.
[36]
AghaeiE, Al-ShaerE. CVE-driven attack technique prediction with semantic information extraction and a domain-specific language model[J/OL].[2023-08-29].
[37]
LiX, FuH. SecureBERT and LLAMA 2 empowered control area network intrusion detection and classification[J/OL].[2023-08-29].
[38]
ChenY, XuL, LiuK, et al. Event extraction via dynamic multi-pooling convolutional neural networks[C]∥Proceedings of the 53rd Annual Meeting of the Association for Computational Linguistics and the 7th International Joint Conference on Natural Language Processing(Volume 1: Long Papers), Beijing, China, 2015: 167-176.
[39]
YanH, JinX, MengX, et al. Event Detection with Multi-Order Graph Convolution and Aggregated Attention[C]∥Proceedings of the Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing(EMNLP-IJCNLP), Hongkong, China, 2019: 5766-5770.
[40]
LaiV D, NguyenT N, NguyenT H. Event detection: gate diversity and syntactic importance scores for graph convolution neural networks[C]∥Proc of the Conf on Empirical Methods in Natural Language Processing, Online, 2020: 5405-5411.