Return
Graph-Based Anomaly APT Attack Detection via Threat Intelligence
DOI:10.1109/TETC.2026.3665235.png)
Abstract
En 中文
Among Advanced Persistent Threats in recent years, hackers have combined multiple defense evasion techniques to hide themselves from the detection of traditional antivirus software. For example, the combination of fileless malware and Living Off the Land techniques and abusing legitimate cloud services force the enterprises have gradually adopted the Endpoint Detection and Response (EDR) instead. However, EDR has the disadvantage that this tool may produce massive false alarms. This situation force security maintainer and analysts to be burdened with a large amount of additional analyses. We proposed an anomaly detection system based on graphs. First, we input a provenance graph containing threat intelligence constructed by the normal behaviors of the system. After that, the system learns the potential structured information from the provenance graph for detecting the abnormal behavior of a host. The results show that the proposed system can effectively detect abnormal event logs. Moreover, we reduce the number of false alarms by up to 97.67%. The improvement dramatically reduces the heavy burdens on the security maintainers from the analyses of the records. Furthermore, the performance of the designed system shows that the abnormal detection based on the graph neural network is superior to a traditional neural network.
Keywords:
Advanced persistent threat (APT)
living off the land (LOTL)
endpoint detection and response (EDR)
threat intelligence
provenance graph
anomaly detection
graph neural network
Journal
IF:
5.4
Papers:
1.1K
Citations:
3.4K

