As Advanced Persistent Threats (APTs) continue to evolve in terms of stealth and persistence, traditional provenance graph-based intrusion detection systems face two core challenges: 1) provenance graphs often contain numerous redundant edges, which can easily introduce noise interference; 2) traditional Graph Neural Networks (GNNs) is difficult to capture the interaction of low-order semantic features in provenance graphs, which limits the detection performance. To address these challenges, we propose PGAE—a perturbation-based graph autoencoder framework that integrates explicit and implicit feature interactions, achieving unsupervised APT node detection. PGAE innovatively applies a dual-edge-node masking mechanism to perturb the structure of provenance graphs. It then synchronously learns explicit interaction patterns and implicit dependencies of node features through an improved graph autoencoder, leveraging a cross-correlation decoder for dual optimization of feature reconstruction and topology rebuilding. Experiments show that PGAE significantly outperforms mainstream methods in terms of accuracy across multiple APT detection datasets, validating its effectiveness and practical applicability.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

PGAE: A Perturbed Graph Autoencoder Integrating Explicit and Implicit Features for APT Detection

  • Chunbo Liu,
  • Chunmiao Xiang,
  • Mengyao Han,
  • Xuying Meng,
  • Wenli Song

摘要

As Advanced Persistent Threats (APTs) continue to evolve in terms of stealth and persistence, traditional provenance graph-based intrusion detection systems face two core challenges: 1) provenance graphs often contain numerous redundant edges, which can easily introduce noise interference; 2) traditional Graph Neural Networks (GNNs) is difficult to capture the interaction of low-order semantic features in provenance graphs, which limits the detection performance. To address these challenges, we propose PGAE—a perturbation-based graph autoencoder framework that integrates explicit and implicit feature interactions, achieving unsupervised APT node detection. PGAE innovatively applies a dual-edge-node masking mechanism to perturb the structure of provenance graphs. It then synchronously learns explicit interaction patterns and implicit dependencies of node features through an improved graph autoencoder, leveraging a cross-correlation decoder for dual optimization of feature reconstruction and topology rebuilding. Experiments show that PGAE significantly outperforms mainstream methods in terms of accuracy across multiple APT detection datasets, validating its effectiveness and practical applicability.