arXiv:2411.10279cs.CRcs.AI2024-11被引 3

基于时间感知子图分析,从认证日志中检测横向移动攻击

Lateral Movement Detection via Time-aware Subgraph Classification on Authentication Logs

  • 构建异构多图捕捉内部实体关联,结合时间特征提取子图
  • 多尺度注意力编码器识别异常行为模式,提升检测准确率
  • 适用于企业网络威胁检测,尤其适合防御隐蔽型入侵

横向移动是高级持续性威胁(APT)攻击的关键环节。攻击者在初始渗透后,利用内网或物联网设备的安全漏洞扩大控制范围,窃取敏感数据或实施其他恶意行为,对系统安全构成严重威胁。现有方法难以发现攻击者通过看似无关操作隐藏真实意图的行为。本文从图视角分析主机认证日志,提出名为LMDetect的多尺度横向移动检测框架:1)从认证日志构建异构多图以增强内部系统实体间的关联性;2)设计时间感知子图生成器,从异构认证多图中提取以认证事件为中心的子图;3)设计多尺度注意力编码器,结合局部与全局注意力机制,捕捉认证子图中的隐藏异常行为模式,实现横向移动检测。在两个真实世界认证日志数据集上的大量实验表明,该框架在检测横向移动行为方面具有显著有效性与优越性。

原文摘要 · Abstract (English)

Lateral movement is a crucial component of advanced persistent threat (APT) attacks in networks. Attackers exploit security vulnerabilities in internal networks or IoT devices, expanding their control after initial infiltration to steal sensitive data or carry out other malicious activities, posing a serious threat to system security. Existing research suggests that attackers generally employ seemingly unrelated operations to mask their malicious intentions, thereby evading existing lateral movement detection methods and hiding their intrusion traces. In this regard, we analyze host authentication log data from a graph perspective and propose a multi-scale lateral movement detection framework called LMDetect. The main workflow of this framework proceeds as follows: 1) Construct a heterogeneous multigraph from host authentication log data to strengthen the correlations among internal system entities; 2) Design a time-aware subgraph generator to extract subgraphs centered on authentication events from the heterogeneous authentication multigraph; 3) Design a multi-scale attention encoder that leverages both local and global attention to capture hidden anomalous behavior patterns in the authentication subgraphs, thereby achieving lateral movement detection. Extensive experiments on two real-world authentication log datasets demonstrate the effectiveness and superiority of our framework in detecting lateral movement behaviors.

横向移动图神经网络威胁检测认证日志

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。