PROV-GEM - Automated Provenance Analysis Framework using Graph Embeddings.

ICMLA(2021)

引用 2|浏览1
暂无评分
摘要
Data provenance graphs, detailed traces of system behavior, are a popular construct to analyze and forecast malicious cyber activity like advanced persistent threats (APT). A critical limitation of existing analysis techniques is the lack of an automated analytic framework to predict APTs. In this work, we address that limitation by augmenting efficient capture and storage mechanisms to include automated analysis. Specifically, we propose P Roy-GEM, a deep graph learning framework to identify malicious anomalous behavior from provenance data. Since data provenance graphs are complex datasets often expressed as heterogeneous attributed multiplex networks, we use a unified relation-aware embedding framework to capture the necessary contexts and associated interactions between the various entities manifest in the data. Furthermore, provenance graphs by nature are rich detailed structures that are heavily attributed compared to other complex systems that have been used traditionally in graph machine learning applications. Towards that end, our framework uniquely captures "multi-embeddings" that can represent varied contexts of nodes and their multi-faceted nature. We demonstrate the efficacy of our embeddings by applying P Roy-GEM to two publicly available APT provenance graph datasets from StreamSpot and Unicorn. P Roy-GEM achieves strong performance on both datasets with a 99% accuracy and 97% Fl-score on the StreamSpot dataset, and a 97% accuracy and 89% Fl-score on the Unicorn dataset, equaling or outperforming comparable state-of-the-art APT threat detection models. Unlike other frameworks, PRov-GEM utilizes an efficient graph convolutional approach coupled with relational self-attention to generate rich graph embeddings that capture the complex topology of data provenance graphs, providing an effective automated analytic framework for APT detection.
更多
查看译文
关键词
cybersecurity,network embeddings,semantic attention,provenance graphs
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要