arrow
Return

Graph-based detection of multi-step attacks using graph convolutional networks

delete2026-05-23
delete0
delete
OA
AI
S
SU Shaukat *
S
Saad Khan
S
Simon Parkinson
DOI:10.1016/j.jisa.2026.104447delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Multi-step attacks, including advanced persistent threats (APT), distributed denial of service (DDoS) and botnets, are still among the most sophisticated threats that modern organisations are experiencing today. Most traditional methods of detecting these threats have difficulties identifying unknown types of events from unknown sources. In this study, we introduce a reproducible GCN-based event-log correlation framework for Multi-step attack detection. In this work, we replicated GC-PTransE for APT reasoning (Phase-1), then extended GC-PTransE into practical lightweight variants for DDoS and Botnet detection (Phase-3) using a common PyG graph interface. Our models demonstrated significant improvements over all categories of attacks. Using the CICIDS2017 (DDoS) dataset, our model achieved 98% accuracy, 100% precision, and 94% recall. With the CTU-13 (Botnet) dataset, GETrans++ achieved 98% accuracy, 100% precision, and 47% recall. The 72% APT-relevance hit rate from our Phase 1 replication demonstrates that GCN can be deployed, providing good efficiency. Finally, by using neighbourhood batching, we avoided the need to store entire graphs in memory, thereby allowing for deployments on commodity CPU/GPU architectures. Limitations of this study included the class imbalance in enterprise logs (Phase 2) and the lack of heterogeneous operational datasets, both of which were identified as areas for future study.
Keywords:
Graph convolutional networks (GCN)
Multi-step attack detection
Event-log correlation
APT detection
DDoS detection
Botnet detection
Heterogeneous datasets
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
2.0K
Citations:
4.9K

Organization

U
university of huddersfield
Scholars:
607
Papers: 306
Citations: 0
Cited Papers

Cited Papers

A Review on Multi-Step Attack Detection
err2025-01-01
err0
PREAI
errShaukat,Syed Usman; Khan,Saad; Parkinson,Simon
errShare
errSave
MCI : Modeling-based Causality Inference in Audit Logging for Attack Investigation
err2018-01-01
err0
errOAAI
errYonghwi Kwon; Fei Wang; Weihang Wang; Kyu Hyung Lee; Wen-Chuan Lee; Shiqing Ma; Xiangyu Zhang; Dongyan Xu; Somesh Jha; Gabriela Ciocarlie; Ashish Gehani; Vinod Yegneswaran
errShare
errSave
Key Vulnerable Nodes Discovery Based on Bayesian Attack Subgraphs and Improved Fuzzy C-Means Clustering
err
err0
PREAI
errXu,Yuhua; Liu,Yang; Sun,Zhixin; Xue,Yucheng; Liao,Weiliang; Liu,Chenlei; Sun,Zhe
errShare
errSave
Method for Extracting Patterns of Coordinated Network Attacks on Electric Power CPS Based on Temporal&x2013;Topological Correlation
err2020-01-01
err17
errOAAI
errWang, Lei; Qu, Zhaoyang; Li, Yang; Hu, Kewei; Sun, Jian; Xue, Kai; Cui, Mingshi
errShare
errSave
researcher View more