贵重. Research on deep security detection technology of multi-source data based on ATT&CK[J]. 2020, 33(10): 81-86. DOI: 10.13992/j.cnki.tetas.2020.10.015.
The detection of APT attack has become an important content of implementing the requirements of network security law. Based on the ATT&CK model
which describes attack tactics and attack techniques
this paper proposes a deep security monitoring model for multi-source data. This model can analyze and present the whole picture of APT attack in the early stage. The current network practice case veri? es that the model proposed in this paper can effectively improve the ability of security defense and response.