Joint Spatial-Temporal Representation for Host Intrusion Detection System
摘要
Host-based Intrusion Detection Systems (HIDS) collect host system logs and generate alerts when the host is attacked. However, existing research fails to adequately capture the spatiotemporal relationships within host behaviors, limiting the accuracy of their representation and modeling. To address this, we propose a spatiotemporal graph representation learning method. This method extracts key data from system logs to construct provenance graphs. A spatiotemporal joint encoder decomposes features along spatial and temporal dimensions independently, then aggregates them to capture spatiotemporal dependencies, explicitly modeling these relationships in host behavior. Experiments on the Streamspot and DARPA-Theia datasets show that the proposed method effectively captures interaction patterns and outperforms baseline models in recall rate, false positive rate, and other evaluation metrics.