• Home
  • Search
  • Detecting APT-Exploited Processes through Semantic Fusion and Interaction Prediction
  • Cite Icon5
  • https://doi.org/10.32604/cmc.2023.045739Copy DOI Icon

Detecting APT-Exploited Processes through Semantic Fusion and Interaction Prediction

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Considering the stealthiness and persistence of Advanced Persistent Threats (APTs), system audit logs are leveraged in recent studies to construct system entity interaction provenance graphs to unveil threats in a host. Rule-based provenance graph APT detection approaches require elaborate rules and cannot detect unknown attacks, and existing learning-based approaches are limited by the lack of available APT attack samples or generally only perform graph-level anomaly detection, which requires lots of manual efforts to locate attack entities. This paper proposes an APT-exploited process detection approach called ThreatSniffer, which constructs the benign provenance graph from attack-free audit logs, fits normal system entity interactions and then detects APT-exploited processes by predicting the rationality of entity interactions. Firstly, ThreatSniffer understands system entities in terms of their file paths, interaction sequences, and the number distribution of interaction types and uses the multi-head self-attention mechanism to fuse these semantics. Then, based on the insight that APT-exploited processes interact with system entities they should not invoke, ThreatSniffer performs negative sampling on the benign provenance graph to generate non-existent edges, thus characterizing irrational entity interactions without requiring APT attack samples. At last, it employs a heterogeneous graph neural network as the interaction prediction model to aggregate the contextual information of entity interactions, and locate processes exploited by attackers, thereby achieving fine-grained APT detection. Evaluation results demonstrate that anomaly-based detection enables ThreatSniffer to identify all attack activities. Compared to the node-level APT detection method APT-KGL, ThreatSniffer achieves a 6.1% precision improvement because of its comprehensive understanding of entity semantics.

Similar Papers
  • PDF
  • Research Article
  • Citations14

ConGraph: Advanced Persistent Threat Detection Method Based on Provenance Graph Combined with Process Context in Cyber-Physical System Environment

  • Feb 29, 2024
  • Electronics
  • Linrui Li +1
  • Research Article
  • Citations50

A Hierarchical Approach for Advanced Persistent Threat Detection with Attention-Based Graph Neural Networks

  • May 04, 2021
  • Security and Communication Networks
  • Zitong Li +4
  • Conference Article

Advanced Persistent Threat (APT) Detection Using Context-Aware Machine Learning Models

  • Jun 19, 2025
  • R N Bhavanavika +1
  • Research Article
  • Citations128

Conan: A Practical Real-Time APT Detection System With High Accuracy and Efficiency

  • Feb 04, 2020
  • IEEE Transactions on Dependable and Secure Computing
  • Chunlin Xiong +8
  • Research Article

Cyber Guardian : Intelligent Threat Surveillance

  • Feb 08, 2024
  • International Journal of Advanced Research in Science, Communication and Technology
  • Aditi H R +2
  • PDF
  • Research Article
  • Citations24

Machine Learning for APT Detection

  • Sep 16, 2023
  • Sustainability
  • Abdullah Said Al-Aamri +5
  • Supplementary Content

Hybrid Time-Position Embedding for Provenance-Based Intrusion Detection

  • Nov 19, 2025
  • Preprints.org
  • Seonghyeon Gong +2
  • PDF
  • Research Article
  • Citations78

Hidden Markov Models and Alert Correlations for the Prediction of Advanced Persistent Threats

  • Jan 01, 2019
  • IEEE Access
  • Ibrahim Ghafir +6
  • Book Chapter
  • Citations14

Multi-stage Dynamic Information Flow Tracking Game

  • Jan 01, 2018
  • Shana Moothedath +5
  • Research Article
  • Citations25

T-Trace: Constructing the APTs Provenance Graphs Through Multiple Syslogs Correlation

  • May 01, 2024
  • IEEE Transactions on Dependable and Secure Computing
  • Teng Li +5
  • Research Article
  • Citations286

Detection of advanced persistent threat using machine-learning correlation analysis

  • Jul 06, 2018
  • Future Generation Computer Systems
  • Ibrahim Ghafir +6
  • Conference Article
  • Citations4

A Graph Learning Approach with Audit Records for Advanced Attack Investigation

  • Dec 04, 2022
  • Jian Liu +4
  • Conference Article

RDD: Real-time Dynamic Detection of APT Attacks Based on Provenance Graph Matching

  • Dec 03, 2025
  • Yuzhang Tian +5
  • Research Article

Adaptive Detection of Advanced Persistent Threats (APT) With Graph Neural Networks and Rehearsal-Based Continual Learning on Wazuh EDR Telemetry

  • Jan 01, 2025
  • IEEE Access
  • Auttapon Pomsathit
  • Research Article
  • Citations7

Sequence feature extraction-based APT attack detection method with provenance graphs

  • Aug 01, 2022
  • SCIENTIA SINICA Informationis
  • 若舟 梁 +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.