Lijuan Xu , ZiCheng Zhao , Dawei Zhao , Xin Li , XiYu Lu , DingYu Yan
{"title":"AJSAGE: A intrusion detection scheme based on Jump-Knowledge Connection To GraphSAGE","authors":"Lijuan Xu , ZiCheng Zhao , Dawei Zhao , Xin Li , XiYu Lu , DingYu Yan","doi":"10.1016/j.cose.2024.104263","DOIUrl":null,"url":null,"abstract":"<div><div>In the field of network security, attackers often utilize Advanced Persistent Threats (APT) to conduct host-based intrusions for prolonged information gathering, penetration and to cause serious damages. Recent studies have used provenance data containing rich contextual information to achieve effective detection of host-based APT. Extracting system entities (e.g., processes, files) and operations between entities in provenance data to construct a directed acyclic graph (DAG) is the key to realize attack detection by provenance graph. Previous studies extracted the features of the whole provenance graph, which did not fully capture the relationship between the nodes in the graph, and the extracted features were not accurate enough. Moreover, the original node feature information may be lost in the process of aggregation. Therefore, abnormal nodes are recognized in the detection process, leading to low detection performance and a high false alarm rate. Facing the challenge, we introduce AJSAGE, a framework based on graph neural networks. A novel anomaly detection method by adding attention mechanism and Jump-Knowledge Connection to GraphSAGE. It enables the integration of node information across hierarchical levels, improves the detection of complex attack patterns, and enhances the accuracy and generalization of the model in node feature representation. It is able to identify features and nodes that are closely related to the anomaly detection task in a more focused manner. We evaluate the performance of AJSAGE on three publicly available datasets, and the results demonstrate that it significantly outperforms multiple state-of-the-art methods for host intrusion detection.</div></div>","PeriodicalId":51004,"journal":{"name":"Computers & Security","volume":"150 ","pages":"Article 104263"},"PeriodicalIF":4.8000,"publicationDate":"2024-12-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computers & Security","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0167404824005698","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
In the field of network security, attackers often utilize Advanced Persistent Threats (APT) to conduct host-based intrusions for prolonged information gathering, penetration and to cause serious damages. Recent studies have used provenance data containing rich contextual information to achieve effective detection of host-based APT. Extracting system entities (e.g., processes, files) and operations between entities in provenance data to construct a directed acyclic graph (DAG) is the key to realize attack detection by provenance graph. Previous studies extracted the features of the whole provenance graph, which did not fully capture the relationship between the nodes in the graph, and the extracted features were not accurate enough. Moreover, the original node feature information may be lost in the process of aggregation. Therefore, abnormal nodes are recognized in the detection process, leading to low detection performance and a high false alarm rate. Facing the challenge, we introduce AJSAGE, a framework based on graph neural networks. A novel anomaly detection method by adding attention mechanism and Jump-Knowledge Connection to GraphSAGE. It enables the integration of node information across hierarchical levels, improves the detection of complex attack patterns, and enhances the accuracy and generalization of the model in node feature representation. It is able to identify features and nodes that are closely related to the anomaly detection task in a more focused manner. We evaluate the performance of AJSAGE on three publicly available datasets, and the results demonstrate that it significantly outperforms multiple state-of-the-art methods for host intrusion detection.
期刊介绍:
Computers & Security is the most respected technical journal in the IT security field. With its high-profile editorial board and informative regular features and columns, the journal is essential reading for IT security professionals around the world.
Computers & Security provides you with a unique blend of leading edge research and sound practical management advice. It is aimed at the professional involved with computer security, audit, control and data integrity in all sectors - industry, commerce and academia. Recognized worldwide as THE primary source of reference for applied research and technical expertise it is your first step to fully secure systems.