• Home
  • Search
  • Using Causality-Driven Graph Representation Learning for APT Attacks Path Identification
  • https://doi.org/10.3390/sym17091373Copy DOI Icon

Using Causality-Driven Graph Representation Learning for APT Attacks Path Identification

Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

In the cybersecurity attack and defense space, the “attacker” and the “defender” form a dynamic and symmetrical adversarial pair. Their strategy iterations and capability evolutions have long been in a symmetrical game of mutual restraint. We will introduce modern Intrusion Detection Systems (IDSs) from the defender’s side to counter the techniques designed by the attacker (APT attack). One major challenge faced by IDS is to identify complex attack paths from a vast provenance graph. By constructing an attack behavior tracking graph, the interactions between system entities can be recorded, but the malicious activities of attackers are often hidden among a large number of normal system operations. Although traditional methods can identify attack behaviors, they only focus on the surface association relationships between entities and ignore the deep causal relationships, which limits the accuracy and interpretability of detection. Existing graph anomaly detection methods usually assign the same weight to all interactions, while we propose a Causal Autoencoder for Graph Explanation (CAGE) based on reinforcement learning. This method extracts feature representations from the traceability graph through a graph attention network(GAT), uses Q-learning to dynamically evaluate the causal importance of edges, and highlights key causal paths through a weight layering strategy. In the DARPA TC project, the experimental results conducted on the selected three datasets indicate that the precision of this method in the anomaly detection task remains above 97% on average, demonstrating excellent accuracy. Moreover, the recall values all exceed 99.5%, which fully proves its extremely low rate of missed detections.

Similar Papers
  • Book Chapter
  • Citations3

Research of Snort Rule Extension and APT Detection Based on APT Network Behavior Analysis

  • Jan 01, 2019
  • Yan Cui +4
  • Conference Article
  • Citations24

Ontology Based APT Attack Behavior Analysis in Cloud Computing

  • Nov 01, 2015
  • Junho Choi +3
  • Research Article
  • Citations3

Dynamic Reconfiguration Method of Active Distribution Networks Based on Graph Attention Network Reinforcement Learning

  • Apr 17, 2025
  • Energies
  • Chen Guo +2
  • Research Article
  • Citations57

A new ensemble deep graph reinforcement learning network for spatio-temporal traffic volume forecasting in a freeway network

  • Jan 29, 2022
  • Digital Signal Processing
  • Pan Shang +5
  • Conference Article

Intelligent Anomaly Detection in Database Security: A Triple-Loop Learning Framework

  • May 19, 2025
  • William Kandolo
  • Conference Article

Detecting Computer Network Anomaly with Data Mining Technology

  • Jan 01, 2015
  • Zhiyu Hu +1
  • Research Article

COGNITIVE APPROACH IN INFORMATION AND CYBER SECURITY

  • Jan 01, 2025
  • Cybersecurity: Education, Science, Technique
  • Svitlana Shevchenko +2
  • Dissertation

Securing Intrusion Detection Systems in IoT Networks Against Adversarial Learning: A Moving Target Defense Approach based on Reinforcement Learning

  • Aug 23, 2023
  • Arnold Brendan Osei
  • Conference Article

Timing Strategy for Active Detection of APT Attack Based on FlipIt Model and Q-learning Method

  • Dec 03, 2021
  • Zhilin Liu +5
  • Research Article
  • Citations22

ANOGAT-Sparse-TL: A hybrid framework combining sparsification and graph attention for anomaly detection in attributed networks using the optimized loss function incorporating the Twersky loss for improved robustness

  • Feb 01, 2025
  • Knowledge-Based Systems
  • Wasim Khan +1
  • Conference Article

Adaptive Cyber Attack Projection through Context-Driven Model Selection: Combining Graph Attention Networks and Reinforcement Learning

  • May 19, 2025
  • Mouhamadou Lamine Diakhame +2
  • Research Article
  • Citations11

Off-policy actor-critic deep reinforcement learning methods for alert prioritization in intrusion detection systems

  • Apr 18, 2024
  • Computers & Security
  • Lalitha Chavali +4
  • Research Article
  • Citations3

Graph Neural Networks for Blockchain Security: A Deep Learning Approach to Anomaly Detection

  • Mar 20, 2025
  • Frontiers in Interdisciplinary Applied Science
  • Alice Laurent
  • PDF
  • Research Article
  • Citations35

Constructing APT Attack Scenarios Based on Intrusion Kill Chain and Fuzzy Clustering

  • Jan 01, 2017
  • Security and Communication Networks
  • Ru Zhang +3
  • Research Article

Smarter Recommendations with Attention: A Survey of Recommendation Systems and the Graph Attention Technique

  • Jan 05, 2026
  • International Journal For Multidisciplinary Research
  • Sandhya M +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.