ICASSP 2025accepted0 citations

RAS-GNN: Reconstructing APT Attack Scenario Using Graph Neural Network

Zhicheng Huang, Ping Wang

Abstract

As a kind of multi-step attack, the APT attack is long-term, highly hidden, and usually exploits novel vulnerabilities. To detect and respond to APT attacks, security analysts need to analyze a large number of system logs and network traffic to determine the sequence of activities executed by APT attacks. Provenance graph is an effective approach to determining the sequence of APT attacks and reconstructing the APT attack scenario for detection and defense. However, its weakness of relying on prior knowledge and difficulty in fine-grained detection of attack behavior hinder provenance graph in practice. In this paper, we propose RAS-GNN, a graph neural network framework with an attention mechanism to reconstruct the APT attack scenario, without prior knowledge. We embed the attributes of attack nodes and their edges in provenance graph, and use the state transition information. We evaluated RAS-GNN’s ability to detect APT attacks and reconstruct APT attack scenarios on 10 APT attack scenarios. RAS-GNN can detect APT attacks with precision, recall, and F1-score of 95.32%, 99.12%, 97.09%, respectively. Moreover, it has a higher reconstruction ability than other attack scenario reconstruction methods.

BibTeX
@inproceedings{icassp2025_rasgnnreconstruc,
  title = {RAS-GNN: Reconstructing APT Attack Scenario Using Graph Neural Network},
  author = {Zhicheng Huang and Ping Wang},
  booktitle = {ICASSP 2025},
  year = {2025}
}
RAS-GNN: Reconstructing APT Attack Scenario Using Graph Neural Network · ICASSP 2025