Zypkro: A Node-Level Anomaly Detector for Provenance Graphs Based on Nonlinear Interaction and Adaptive Domain Techniques
摘要
Provenance graphs, representing the interactions between entities within computer systems, encapsulate the context and causal relationships of system executions, making them a crucial subject of study in the field of cybersecurity. Recently, leveraging Graph Neural Networks (GNNs) to model provenance graphs for automated host intrusion detection has gained significant attention. However, due to the specific semantics embedded in provenance graphs within the cybersecurity domain, traditional GNN algorithms often struggle with effectively representing node features and differentiating between them, leading to high false positive rates and reduced accuracy in node-level anomaly detectors. To address this challenge, we introduce Zypkro—a host-based node-level anomaly detection system. Zypkro uses provenance graphs as input, focusing on the detection and tracking of covert intrusion activities. The system employs an innovative nonlinear interaction algorithm that captures the causal relationships between nodes and their higher-order neighbors, significantly enhancing feature representation. Additionally, Zypkro incorporates an adaptive weight update mechanism for neighborhood features, improving the efficiency of information utilization and the ability to differentiate between features. Compared to existing state-of-the-art node-level anomaly detectors, Zypkro demonstrates superior performance, particularly in terms of model generalization, detection accuracy, and reducing false positives and negatives. Zypkro offers an efficient, real-time solution for detecting covert threats in the cybersecurity domain, significantly improving the precision and reliability of anomaly detection.