TC-GAT: Temporal Causal Graph Attention for Interpretable APT Detection
Farhan M. Hameed, Antony Taurshia, Jenefa Archpaul
Karunya University
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
In the present day, the concept of APT or Advanced Persistent Threat usually refers to the ongoing security attacks and data problem within a Linux based operation system. Officially driven hacking activities are normally concerned with multiple players who can include the attackers, the safeguarding organization, and neutral players who may support or impede these cyber assaults. However, operational logs are extremely out of balance, with a few malicious events embedded in a huge amount of benign activity, and alerts need to be interpretable to aid analyst triage. Conventional feature-based classifiers and unsupervised anomaly detectors are generally not capable of capturing cross-entity dependencies and multi-stage attack transitions, whereas conventional graph models generally do not make full use of the temporal continuity and also do not explicitly focus on the relations that are causally important. To solve these problems, this paper proposes TC-GAT, a temporal–causal graph attention framework that generates time-ordered heterogeneous graphs from multi-source telemetry and type-aware attention with GRU-based temporal aggregation, while introducing causal weighting to handle the attack–relevant dependencies. Experiments are run on the APT Evaluation Dataset for Linux 2024 with over 50 million events sampled from syslog, auth.log, file-system audit, and network PCAP and 10M benign and 5K malicious events in 5 attack stages, in the form of 1 hour snapshots and 50% overlap. TC-GAT achieves a precision of 0.92, recall of 0.94, F1-score of 0.93, and AUC of 0.98, which is better than a GCN baseline (F1-score 0.87, AUC 0.93), and ablation results show the contribution of causal weighting, temporal aggregation, and heterogeneous attention with F1-scores of 0.88, 0.86, and 0.84 when each one is removed. The model is compact (0.28M parameters) and enables close to real-time inference (50 ms to infer one snapshot) with accurate detection and short evidence paths that correspond to attack progress.
逐年被引趋势
暂无年度引用数据
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIExplainable Artificial Intelligence (XAI)
Bayesian Modeling and Causal Inference · Adversarial Robustness in Machine Learning
参考文献 24
此处列出前 3 条