APT Attack Detection Based on Graph Convolutional Neural Networks

被引:0
|
作者
Weiwu Ren
Xintong Song
Yu Hong
Ying Lei
Jinyu Yao
Yazhou Du
Wenjuan Li
机构
[1] Changchun University of Science and Technology,School of Computer Science and Technology
[2] National Computer Network Emergency Response Center,Jilin Branch
关键词
APT attack detection; Graph convolutional neural networks; Knowledge graph; Vulnerability exploits;
D O I
暂无
中图分类号
学科分类号
摘要
Advanced persistent threat (APT) attacks are malicious and targeted forms of cyberattacks that pose significant challenges to the information security of governments and enterprises. Traditional detection methods struggle to extract long-term relationships within these attacks effectively. This paper proposes an APT attack detection model based on graph convolutional neural networks (GCNs) to address this issue. The aim is to detect known attacks based on vulnerabilities and attack contexts. We extract organization-vulnerability relationships from publicly available APT threat intelligence, along with the names and relationships of software security entities from CVE, CWE, and CAPEC, to generate triple data and construct a knowledge graph of APT attack behaviors. This knowledge graph is transformed into a homogeneous graph, and GCNs are employed to process graph features, enabling effective APT attack detection. We evaluate the proposed method on the dataset constructed in this paper. The results show that the detection accuracy of the GCN method reaches 95.9%, improving by approximately 2.1% compared to the GraphSage method. This approach proves to be effective in real-world APT attack detection scenarios.
引用
收藏
相关论文
共 50 条
  • [21] Graph-based APT detection
    Debatty, Thibault
    Mees, Wim
    Gilon, Thomas
    2018 INTERNATIONAL CONFERENCE ON MILITARY COMMUNICATIONS AND INFORMATION SYSTEMS (ICMCIS), 2018,
  • [22] AIGCN: Attack Intention Detection for Power System Using Graph Convolutional Networks
    Tang, Qiuhang
    Chen, Huadong
    Ge, Binbin
    Wang, Haoyu
    JOURNAL OF SIGNAL PROCESSING SYSTEMS FOR SIGNAL IMAGE AND VIDEO TECHNOLOGY, 2022, 94 (11): : 1119 - 1127
  • [23] Rumour Detection Based on Graph Convolutional Neural Net
    Bai, Na
    Meng, Fanrong
    Rui, Xiaobin
    Wang, Zhixiao
    IEEE ACCESS, 2021, 9 : 21686 - 21693
  • [24] Fault Detection and Isolation in Industrial Networks using Graph Convolutional Neural Networks
    Khorasgani, Hamed
    Hasanzadeh, Arman
    Farahat, Ahmed
    Gupta, Chetan
    2019 IEEE INTERNATIONAL CONFERENCE ON PROGNOSTICS AND HEALTH MANAGEMENT (ICPHM), 2019,
  • [25] Heart Attack Detection in Colour Images Using Convolutional Neural Networks
    Rojas-Albarracin, Gabriel
    Angel Chaves, Miguel
    Fernandez-Caballero, Antonio
    Lopez, Maria T.
    APPLIED SCIENCES-BASEL, 2019, 9 (23):
  • [26] MULTIPLE POINTS INPUT FOR CONVOLUTIONAL NEURAL NETWORKS IN REPLAY ATTACK DETECTION
    Yoon, Sung-Hyun
    Yu, Ha-Jin
    2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 6444 - 6448
  • [27] Face Spoof Attack Detection with Hypergraph Capsule Convolutional Neural Networks
    Liang, Yuxin
    Hong, Chaoqun
    Zhuang, Weiwei
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2021, 14 (01) : 1396 - 1402
  • [28] Detection of landslide based on convolutional neural networks
    Zhang, Heng
    Chen, Xiaohu
    Song, Zhizhong
    Zhan, Weijie
    Lei, Huiguang
    2022 8TH INTERNATIONAL CONFERENCE ON HYDRAULIC AND CIVIL ENGINEERING: DEEP SPACE INTELLIGENT DEVELOPMENT AND UTILIZATION FORUM, ICHCE, 2022, : 736 - 739
  • [29] Resistor Detection Based on Convolutional Neural Networks
    Liu, Chun
    Shi, Yudeng
    2017 IEEE 3RD INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC), 2017, : 91 - 94
  • [30] Cyber security attack recognition on cloud computing networks based on graph convolutional neural network and graphsage models
    Abdullayeva, Fargana
    Suleymanzade, Suleyman
    RESULTS IN CONTROL AND OPTIMIZATION, 2024, 15