Return
EarlyDLM: Early Detecting Lateral Movements Through Graph and Loopback Sequence Embedding
DOI:10.1109/TNSE.2025.3584627.png)
Abstract
En 中文
An adversary may conduct lateral movement (LM), a critical tactic in advanced persistent threats (APTs), to progressively access and control systems within an intranet, advancing toward their ultimate targets. Detecting lateral movement has drawn significant research interest. However, existing work on LM detection exhibits low effectiveness in identifying a LM-based attack at its early stage, defined as attackers only compromise a few hosts before reaching the ultimate targets. In addition, existing methods for early attack detection usually cannot work against LM-based attacks and may incur cumulative detection errors due to the noise propagation in their recursive structures. To bridge this gap, we design a new graph and loopback sequence embedding model for Early Detection of Lateral Movement (EarlyDLM). EarlyDLM first constructs a discrete temporal graph and employs graph embedding models to learn the features of hosts effectively. Then, we introduce a loopback sequence embedding model to predict connections among hosts in the future. The backward inference capability possessed by the loopback sequence embedding model can alleviate cumulative detection errors. Experimental results on three public datasets demonstrate that EarlyDLM can accurately detect early LM events, and work better than other work.
Keywords:
Advanced persistent threat
lateral movement
anomaly detection
graph embedding
sequence embedding
Journal
I
IF:
7.9
Papers:
2.5K
Citations:
10.0K

