Align to Attribute: APT Attribution via Entity-Level Semantic Alignment
Abstract
Threat actor attribution from cyber threat intelligence (CTI) reports commonly predicts actor labels from historical reports. However, many advanced persistent threat (APT) actors have few reports, with evidence fragmented across heterogeneous entities and unstructured text, making reliable attribution difficult for tail actors. We explore entity-level semantic alignment for attribution, comparing unknown and known actors through associated entities and graph contexts. We construct HEAA as a benchmark for long-tail attribution evaluation. Our analysis quantifies the trade-off between evidence discriminativeness and cross-report generalizability and identifies limitations of individual evidence types for attribution. Based on these findings, we proposeThreatAlign, a large language model (LLM)-based alignment framework that recursively integrates selected graph evidence and external knowledge into semantic profiles. The framework combines profile semantics with supporting evidence for cross-graph entity alignment to identify unknown actors. ThreatAlign achieves 43.5% macro-F1 on HEAA, 16.6 percentage points above the strongest evaluated baseline, and remains close to the best methods on conventional attribution (AADM+) and general-purpose entity alignment (ICEWS-WIKI). Our code is available at https://anonymous.4open.science/r/ThreatAlign-31F6/.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.