APT attacks are highly targeted and stealthy, with attackers using customized tools and methods to maintain a long-term presence within the target system. APT detection methods based on deep neural networks have achieved certain results, but as attack methods continue to evolve, these methods require the regular collection and labeling of new data. However, data labeling requires a significant amount of expert knowledge and human labor costs. At the same time, they also face the challenge of attackers imitating normal behavior to evade detection. This paper introduces a novel self-supervised graph representation learning method called AISSGR, which effectively reduces the reliance on a large amount of labeled data by employing unsupervised anomaly detection methods, thereby enhancing the generalization and adaptability of the detection model. By using a masked graph autoencoder, the method obscures part of the graph structure, thus reducing the resources required for training. Additionally, by combining with latent space prediction, the model is able to learn more nuanced information representations, which strengthens its ability to distinguish between unknown threats and behaviors that are similar to normal activities. AISSGR has been evaluated on multiple widely used datasets, and the results show that it can perform precise attack detection with low overhead. Additionally, AISSGR has demonstrated its potential in cross-dataset detection tasks, proving its relative effectiveness in attack detection under a self-supervised setting.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

AISSGR: Attack Investigation Based on Self-supervised Graph Representation Learning

  • Lan Hu,
  • Jianyi Liu,
  • Ru Zhang

摘要

APT attacks are highly targeted and stealthy, with attackers using customized tools and methods to maintain a long-term presence within the target system. APT detection methods based on deep neural networks have achieved certain results, but as attack methods continue to evolve, these methods require the regular collection and labeling of new data. However, data labeling requires a significant amount of expert knowledge and human labor costs. At the same time, they also face the challenge of attackers imitating normal behavior to evade detection. This paper introduces a novel self-supervised graph representation learning method called AISSGR, which effectively reduces the reliance on a large amount of labeled data by employing unsupervised anomaly detection methods, thereby enhancing the generalization and adaptability of the detection model. By using a masked graph autoencoder, the method obscures part of the graph structure, thus reducing the resources required for training. Additionally, by combining with latent space prediction, the model is able to learn more nuanced information representations, which strengthens its ability to distinguish between unknown threats and behaviors that are similar to normal activities. AISSGR has been evaluated on multiple widely used datasets, and the results show that it can perform precise attack detection with low overhead. Additionally, AISSGR has demonstrated its potential in cross-dataset detection tasks, proving its relative effectiveness in attack detection under a self-supervised setting.