Attack Chain Reconstruction Method Based on LLM Prior-Knowledge Guidance and Heterogeneous Graph Reasoning

In the face of multi-stage and cross-device complex network attacks, reconstructing the complete attack link from massive heterogeneous security logs is the core problem of security operation. In the existing methods, the traditional graph model lacks a deep understanding of the semantics of alerts, and large language models (LLMs) have the ability of textual reasoning, but have difficulty effectively using the topology between entities, and have difficulty uniformly representing and globally relating multi-source heterogeneous data. Aiming at the above problems, this paper proposes a heterogeneous graph attack chain reconstruction method based on LLM prior-knowledge guidance. Firstly, ontology schemas of six types of core security entities and four types of relationship types are designed for multi-source security logs, and a unified heterogeneous graph representation is constructed by integrating temporal association, spatial association and semantic association. Events scattered in different devices and time windows are correlated into structured views. Secondly, the domain-adaptive fine-tuned LLM is used to encode the deep semantics of the node attribute text, and it is fused with the structural features to make up for the shortcomings of traditional graph neural networks that only rely on shallow statistical features. On this basis, a heterogeneous graph attention mechanism guided by LLM prior knowledge is designed, the attention weight is modulated by the LLM’s semantic score of edge rationality, and candidate attack links are generated by multi-step path reasoning along high-confidence edges. Finally, the logical verification and attack confirmation of the candidate link were carried out step by step with the help of the chain-of-thought ability of LLM, and the confidence was calibrated by temperature scaling. Experiments on DARPA TC and other datasets show that the integrity rate of attack link reconstruction is 86.4%, the coverage rate of attack phase is 82.1%, and the F1 value of attack confirmation is 90.6%, which is significantly better than the methods based on a probabilistic graph model, Heterogeneous Graph Transformer and pure LLM hint engineering. This verifies the effectiveness of the cooperation between semantic understanding and structural reasoning.

Authors

Institutions

Publication Details

Journal
Electronics
Published
2026-09-22
DOI
https://doi.org/10.3390/electronics15194348
Primary Topic
Advanced Graph Neural Networks
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Attack Chain Reconstruction Method Based on LLM Prior-Knowledge Guidance and Heterogeneous Graph Reasoning

Jinchuan Pei, Huimei Wang, Haoyu Chen, Lin Ni
Electronics
Advanced Graph Neural Networks
article

Attack Chain Reconstruction Method Based on LLM Prior-Knowledge Guidance and Heterogeneous Graph Reasoning

Jinchuan Pei, Huimei Wang, Haoyu Chen, Lin Ni
article en

Abstract

In the face of multi-stage and cross-device complex network attacks, reconstructing the complete attack link from massive heterogeneous security logs is the core problem of security operation. In the existing methods, the traditional graph model lacks a deep understanding of the semantics of alerts, and large language models (LLMs) have the ability of textual reasoning, but have difficulty effectively using the topology between entities, and have difficulty uniformly representing and globally relating multi-source heterogeneous data. Aiming at the above problems, this paper proposes a heterogeneous graph attack chain reconstruction method based on LLM prior-knowledge guidance. Firstly, ontology schemas of six types of core security entities and four types of relationship types are designed for multi-source security logs, and a unified heterogeneous graph representation is constructed by integrating temporal association, spatial association and semantic association. Events scattered in different devices and time windows are correlated into structured views. Secondly, the domain-adaptive fine-tuned LLM is used to encode the deep semantics of the node attribute text, and it is fused with the structural features to make up for the shortcomings of traditional graph neural networks that only rely on shallow statistical features. On this basis, a heterogeneous graph attention mechanism guided by LLM prior knowledge is designed, the attention weight is modulated by the LLM’s semantic score of edge rationality, and candidate attack links are generated by multi-step path reasoning along high-confidence edges. Finally, the logical verification and attack confirmation of the candidate link were carried out step by step with the help of the chain-of-thought ability of LLM, and the confidence was calibrated by temperature scaling. Experiments on DARPA TC and other datasets show that the integrity rate of attack link reconstruction is 86.4%, the coverage rate of attack phase is 82.1%, and the F1 value of attack confirmation is 90.6%, which is significantly better than the methods based on a probabilistic graph model, Heterogeneous Graph Transformer and pure LLM hint engineering. This verifies the effectiveness of the cooperation between semantic understanding and structural reasoning.

ElectronicsVol. 15(19)
National University of Defense Technology (CN), Wuhan University (CN)
Partnerships for the goals
Openalex Percentile: Top 8%
Advanced Graph Neural Networks
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.