APT Attack Detection Based on Graph Convolutional Neural Networks

被引:0
|
作者
Weiwu Ren
Xintong Song
Yu Hong
Ying Lei
Jinyu Yao
Yazhou Du
Wenjuan Li
机构
[1] Changchun University of Science and Technology,School of Computer Science and Technology
[2] National Computer Network Emergency Response Center,Jilin Branch
关键词
APT attack detection; Graph convolutional neural networks; Knowledge graph; Vulnerability exploits;
D O I
暂无
中图分类号
学科分类号
摘要
Advanced persistent threat (APT) attacks are malicious and targeted forms of cyberattacks that pose significant challenges to the information security of governments and enterprises. Traditional detection methods struggle to extract long-term relationships within these attacks effectively. This paper proposes an APT attack detection model based on graph convolutional neural networks (GCNs) to address this issue. The aim is to detect known attacks based on vulnerabilities and attack contexts. We extract organization-vulnerability relationships from publicly available APT threat intelligence, along with the names and relationships of software security entities from CVE, CWE, and CAPEC, to generate triple data and construct a knowledge graph of APT attack behaviors. This knowledge graph is transformed into a homogeneous graph, and GCNs are employed to process graph features, enabling effective APT attack detection. We evaluate the proposed method on the dataset constructed in this paper. The results show that the detection accuracy of the GCN method reaches 95.9%, improving by approximately 2.1% compared to the GraphSage method. This approach proves to be effective in real-world APT attack detection scenarios.
引用
收藏
相关论文
共 50 条
  • [1] APT Attack Detection Based on Graph Convolutional Neural Networks
    Ren, Weiwu
    Song, Xintong
    Hong, Yu
    Lei, Ying
    Yao, Jinyu
    Du, Yazhou
    Li, Wenjuan
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2023, 16 (01)
  • [2] Anomaly detection with convolutional Graph Neural Networks
    Oliver Atkinson
    Akanksha Bhardwaj
    Christoph Englert
    Vishal S. Ngairangbam
    Michael Spannowsky
    Journal of High Energy Physics, 2021
  • [3] Anomaly detection with convolutional Graph Neural Networks
    Atkinson, Oliver
    Bhardwaj, Akanksha
    Englert, Christoph
    Ngairangbam, Vishal S.
    Spannowsky, Michael
    JOURNAL OF HIGH ENERGY PHYSICS, 2021, 2021 (08)
  • [4] Graph Convolutional Networks for DDoS Attack Detection in a Lossy Network
    Hekmati, Arvin
    Krishnamachari, Bhaskar
    2024 IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING FOR COMMUNICATION AND NETWORKING, ICMLCN 2024, 2024, : 158 - 163
  • [5] User similarity-based graph convolutional neural network for shilling attack detection
    Zhang, Yan
    Hao, Qingbo
    Zheng, Wenguang
    Xiao, Yingyuan
    APPLIED INTELLIGENCE, 2025, 55 (05)
  • [6] Conformalized Adversarial Attack Detection for Graph Neural Networks
    Ennadir, Sofiane
    Alkhatib, Amr
    Bostrom, Henrik
    Vazirgiannis, Michalis
    CONFORMAL AND PROBABILISTIC PREDICTION WITH APPLICATIONS, VOL 204, 2023, 204 : 311 - 323
  • [7] Convolutional neural network based evil twin attack detection in WiFi networks
    Tian, Yinghua
    Wang, Sheng
    Zhang, Long
    2020 2ND INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE COMMUNICATION AND NETWORK SECURITY (CSCNS2020), 2021, 336
  • [8] Cyber-Physical Attack Detection in Water Distribution Systems with Temporal Graph Convolutional Neural Networks
    Tsiami, Lydia
    Makropoulos, Christos
    WATER, 2021, 13 (09)
  • [9] Graph-based saliency and ensembles of convolutional neural networks for glaucoma detection
    Serte, Sertan
    Serener, Ali
    IET IMAGE PROCESSING, 2021, 15 (03) : 797 - 804
  • [10] On the Use of Convolutional Neural Networks for Speech Presentation Attack Detection
    Korshunov, P.
    Goncalves, A. R.
    Violato, R. P. V.
    Simoes, F. O.
    Marcel, S.
    2018 IEEE 4TH INTERNATIONAL CONFERENCE ON IDENTITY, SECURITY, AND BEHAVIOR ANALYSIS (ISBA), 2018,