Provenance graphs, representing the interactions between entities within computer systems, encapsulate the context and causal relationships of system executions, making them a crucial subject of study in the field of cybersecurity. Recently, leveraging Graph Neural Networks (GNNs) to model provenance graphs for automated host intrusion detection has gained significant attention. However, due to the specific semantics embedded in provenance graphs within the cybersecurity domain, traditional GNN algorithms often struggle with effectively representing node features and differentiating between them, leading to high false positive rates and reduced accuracy in node-level anomaly detectors. To address this challenge, we introduce Zypkro—a host-based node-level anomaly detection system. Zypkro uses provenance graphs as input, focusing on the detection and tracking of covert intrusion activities. The system employs an innovative nonlinear interaction algorithm that captures the causal relationships between nodes and their higher-order neighbors, significantly enhancing feature representation. Additionally, Zypkro incorporates an adaptive weight update mechanism for neighborhood features, improving the efficiency of information utilization and the ability to differentiate between features. Compared to existing state-of-the-art node-level anomaly detectors, Zypkro demonstrates superior performance, particularly in terms of model generalization, detection accuracy, and reducing false positives and negatives. Zypkro offers an efficient, real-time solution for detecting covert threats in the cybersecurity domain, significantly improving the precision and reliability of anomaly detection.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Zypkro: A Node-Level Anomaly Detector for Provenance Graphs Based on Nonlinear Interaction and Adaptive Domain Techniques

  • Yi Zong,
  • Rongrong Chen,
  • Xiaoya Ni,
  • Minghao Hu,
  • Qianlong Xiao,
  • Ximing Chen,
  • Yongxin Cai,
  • Jing Qiu

摘要

Provenance graphs, representing the interactions between entities within computer systems, encapsulate the context and causal relationships of system executions, making them a crucial subject of study in the field of cybersecurity. Recently, leveraging Graph Neural Networks (GNNs) to model provenance graphs for automated host intrusion detection has gained significant attention. However, due to the specific semantics embedded in provenance graphs within the cybersecurity domain, traditional GNN algorithms often struggle with effectively representing node features and differentiating between them, leading to high false positive rates and reduced accuracy in node-level anomaly detectors. To address this challenge, we introduce Zypkro—a host-based node-level anomaly detection system. Zypkro uses provenance graphs as input, focusing on the detection and tracking of covert intrusion activities. The system employs an innovative nonlinear interaction algorithm that captures the causal relationships between nodes and their higher-order neighbors, significantly enhancing feature representation. Additionally, Zypkro incorporates an adaptive weight update mechanism for neighborhood features, improving the efficiency of information utilization and the ability to differentiate between features. Compared to existing state-of-the-art node-level anomaly detectors, Zypkro demonstrates superior performance, particularly in terms of model generalization, detection accuracy, and reducing false positives and negatives. Zypkro offers an efficient, real-time solution for detecting covert threats in the cybersecurity domain, significantly improving the precision and reliability of anomaly detection.