APT Attack Detection Based on Graph Convolutional Neural Networks

被引:2
|
作者
Ren, Weiwu [1 ]
Song, Xintong [1 ]
Hong, Yu [2 ]
Lei, Ying [1 ]
Yao, Jinyu [1 ]
Du, Yazhou [1 ]
Li, Wenjuan [1 ]
机构
[1] Changchun Univ Sci & Technol, Sch Comp Sci & Technol, Changchun 130000, Jilin, Peoples R China
[2] Natl Comp Network Emergency Response Ctr, Jilin Branch, Changchun 130000, Jilin, Peoples R China
关键词
APT attack detection; Graph convolutional neural networks; Knowledge graph; Vulnerability exploits;
D O I
10.1007/s44196-023-00369-5
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advanced persistent threat (APT) attacks are malicious and targeted forms of cyberattacks that pose significant challenges to the information security of governments and enterprises. Traditional detection methods struggle to extract long-term relationships within these attacks effectively. This paper proposes an APT attack detection model based on graph convolutional neural networks (GCNs) to address this issue. The aim is to detect known attacks based on vulnerabilities and attack contexts. We extract organization-vulnerability relationships from publicly available APT threat intelligence, along with the names and relationships of software security entities from CVE, CWE, and CAPEC, to generate triple data and construct a knowledge graph of APT attack behaviors. This knowledge graph is transformed into a homogeneous graph, and GCNs are employed to process graph features, enabling effective APT attack detection. We evaluate the proposed method on the dataset constructed in this paper. The results show that the detection accuracy of the GCN method reaches 95.9%, improving by approximately 2.1% compared to the GraphSage method. This approach proves to be effective in real-world APT attack detection scenarios.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] APT Attack Detection Based on Graph Convolutional Neural Networks
    Weiwu Ren
    Xintong Song
    Yu Hong
    Ying Lei
    Jinyu Yao
    Yazhou Du
    Wenjuan Li
    [J]. International Journal of Computational Intelligence Systems, 16
  • [2] Anomaly detection with convolutional Graph Neural Networks
    Oliver Atkinson
    Akanksha Bhardwaj
    Christoph Englert
    Vishal S. Ngairangbam
    Michael Spannowsky
    [J]. Journal of High Energy Physics, 2021
  • [3] Anomaly detection with convolutional Graph Neural Networks
    Atkinson, Oliver
    Bhardwaj, Akanksha
    Englert, Christoph
    Ngairangbam, Vishal S.
    Spannowsky, Michael
    [J]. JOURNAL OF HIGH ENERGY PHYSICS, 2021, 2021 (08)
  • [4] Conformalized Adversarial Attack Detection for Graph Neural Networks
    Ennadir, Sofiane
    Alkhatib, Amr
    Bostrom, Henrik
    Vazirgiannis, Michalis
    [J]. CONFORMAL AND PROBABILISTIC PREDICTION WITH APPLICATIONS, VOL 204, 2023, 204 : 311 - 323
  • [5] Convolutional neural network based evil twin attack detection in WiFi networks
    Tian, Yinghua
    Wang, Sheng
    Zhang, Long
    [J]. 2020 2ND INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE COMMUNICATION AND NETWORK SECURITY (CSCNS2020), 2021, 336
  • [6] Cyber-Physical Attack Detection in Water Distribution Systems with Temporal Graph Convolutional Neural Networks
    Tsiami, Lydia
    Makropoulos, Christos
    [J]. WATER, 2021, 13 (09)
  • [7] Graph-based saliency and ensembles of convolutional neural networks for glaucoma detection
    Serte, Sertan
    Serener, Ali
    [J]. IET IMAGE PROCESSING, 2021, 15 (03) : 797 - 804
  • [8] On the Use of Convolutional Neural Networks for Speech Presentation Attack Detection
    Korshunov, P.
    Goncalves, A. R.
    Violato, R. P. V.
    Simoes, F. O.
    Marcel, S.
    [J]. 2018 IEEE 4TH INTERNATIONAL CONFERENCE ON IDENTITY, SECURITY, AND BEHAVIOR ANALYSIS (ISBA), 2018,
  • [9] GCNXSS: An Attack Detection Approach for Cross-Site Scripting Based on Graph Convolutional Networks
    Pan, Hongyu
    Fang, Yong
    Huang, Cheng
    Guo, Wenbo
    Wan, Xuelin
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (12): : 4008 - 4023
  • [10] Convolutional Graph Neural Networks
    Gama, Fernando
    Marques, Antonio G.
    Leus, Geert
    Ribeiro, Alejandro
    [J]. CONFERENCE RECORD OF THE 2019 FIFTY-THIRD ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS & COMPUTERS, 2019, : 452 - 456