RShield: A Refined Shield for Complex Multi-step Attack Detection Based on Temporal Graph Network

Yang Weiyong,Gao Peng,Huang Hao,Wei Xingshen,Liu Wei,Zhu Shishun,Luo Wang
DOI: https://doi.org/10.1007/978-3-031-00129-1_40
2022-01-01
Abstract:Complex multi-step attacks (i.e., CMA) have caused severe damage to core information infrastructures of many organizations. The graph-based methods are well known as the ability for learning complex interaction patterns of systems and users with discrete graph snapshots. However, such methods are challenged by the computer networking model characterized by a natural continuous-time dynamic graph. In this paper, we propose RShield, a temporal graph network-based CMA detection and defense method. It first constructs the continuous-time dynamic graph based on interactions among users and entities from various log records. Then it trains the detection model offline and performs streaming detection for live online network events. A prototype of RShield has been implemented. The experimental evaluation shows that RShield can achieve superior detection performance than the state-of-the-art methods in both transductive and inductive settings.
What problem does this paper attempt to address?