Return
NIMBLE: A modular self-supervised GraphSAGE framework for deployable provenance anomaly detection
G
B
Y
X
P
W
Y
G
DOI:10.1016/j.cose.2026.105081.png)
Abstract
En 中文
Provenance graphs are effective for host-based intrusion detection because they encode interactions among system entities, but practical anomaly detection still requires clear separation between representation learning, anomaly scoring, and deployment-time thresholding. We present NIMBLE, a modular self-supervised GraphSAGE framework fitted on benign provenance graphs and paired with a downstream outlier detector. NIMBLE supports configurable attribute corruption, optional edge reconstruction, pooled graph-level or node-level readout, and frozen-embedding scoring with Isolation Forest. We evaluate two thresholding protocols: a strict benign-quantile threshold selection (BQTS) protocol that uses only held-out benign validation scores before blind testing, and a label-tuned protocol reported only as an upper-bound reference for comparison with prior public benchmarks. The main scope supported by our matched-compute evidence is that a GraphSAGE representation with a decoupled iForest scorer is better suited than a MAGIC-style GCNII masked graph autoencoder for node-level DARPA E3 Trace detection under the same training and detector budget. BQTS performs reliably on homogeneous graph-level (StreamSpot) and node-level (Trace) settings but remains unreliable on the low-volume stealthy supply-chain scenario (Wget) under the default benign-q0.95 rule. Five-seed experiments and ablations show that GraphSAGE is the dominant architectural contributor, denoising and edge reconstruction are dataset-dependent regularizers rather than universally beneficial components, and detector choice remains important. The resulting contribution is a practical, batch-memory-efficient provenance representation pipeline that decouples graph encoding from anomaly scoring while making deployment-time thresholding explicit and auditable.
Journal
C
IF:
5.4
Papers:
164
Citations:
0
