Graph Neural Network-Based Detection of Advanced Persistent Threats In Enterprise Networks
Keywords:
Advanced persistent threat, Graph neural network, Enterprise networks, Anomaly detection, Cyber securityAbstract
Among all attack classes, advanced persistent threats (APTs) can be considered one of the most challenging to detect since they comprise multi-stage activities of low-noise nature including reconnaissance, credentials misuse, lateral movements, and data exfiltration. Signature- or flow-based approaches may prove effective against known threats, but they will be ineffective in capturing relations that separate malicious attack paths from legitimate events. This paper offers a graph neural network (GNN)-based approach for the detection of APTs in enterprise environments, where hosts, users, services, and communication events are modeled as a dynamic graph. The proposed approach, which we call GNN-APTNet, converts enterprise telemetry into attributed graphs and utilizes graph learning for the computation of node- and subgraph-level risks based on features computed from the communication, authentication, and process-related events. This paper is written in the manner of an engineering research paper, with a reproducible conceptual evaluation of the work. All figures, diagrams, topology maps, learning curves, and other visuals have been produced locally for the purposes of this work and were not taken from online sources. As a response to the preference of the design of this project, the figures play a more significant role in the paper than tables. Example outcomes show that graph reasoning improves detection of multi-stage attacks by maintaining the context with respect to which entities interact with each other, which entities authenticate in different zones, and what happens in time windows related to each other. The proposed model is compared with basic graph learning approaches, and it turns out that authentication relations, time windows, and process-level context are particularly helpful in distinguishing between normal enterprise behavior and multi-step APT behavior. The authors state that GNNs give an interesting way to go in enterprise security analysis.







3.png)

1.png)

1.png)


3.jpg)