arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

TGL-APT:结合图蒸馏的时序图学习用于高效高级持续性威胁调查

TGL-APT: Temporal Graph Learning with Graph Distillation for Efficient APT Investigation

Jing Chen, Ayong Ye, Yuanhuang Liu, Yuexin Zhang

arXiv 2608.19750首次发表:更新:

AI 中文总结

该研究针对APT攻击检测中全图学习成本高的问题,提出TGL-APT框架,结合图蒸馏、自适应时序图学习等技术,在DARPA E3数据集上实现高检测性能并降低了计算资源消耗。

AI 中文摘要

高级持续性威胁(APT)攻击对现代系统构成严峻挑战,其隐蔽性和多阶段特性使得传统检测方法失效。尽管溯源图为攻击调查提供了丰富的行为上下文,但与攻击相关的证据往往稀疏且嵌入在大量常规系统活动中,这使得全图学习计算成本高昂,且难以关联长攻击序列。我们提出TGL-APT,这是一种自适应调查框架,基于以下观察:与攻击相关的信息分布不均,且通常由具有结构影响力或行为独特性的实体介导,我们将这些实体表征为信息瓶颈节点。TGL-APT结合了三个互补组件:(1)信息瓶颈引导的图蒸馏,该方法在抑制溯源冗余的同时限制结构失真并保留因果可达性;(2)自适应时序图学习,其随着节点相关性的演变不断优化核心节点集;(3)跨时空攻击指纹对齐,该方法关联不同实体和时间窗口中分散的可疑活动。最后,因果扩展和阶段表征重构出连贯的攻击过程以用于调查。在三个DARPA E3数据集上的实验表明,与KAIROS相比,TGL-APT的F1分数分别为95.7%、90.9%和88.9%,同时训练时间、检测延迟和内存使用量分别减少约39%、33%和22%。这些结果表明,TGL-APT在基于溯源图的APT分析中有效平衡了检测性能、计算效率和调查能力。

英文摘要

Advanced Persistent Threat (APT) attacks pose a critical challenge to modern systems, as their stealthy, multi-stage nature renders conventional detection methods ineffective. While provenance graphs provide rich behavioral context for attack investigation, attack-relevant evidence is often sparse and embedded in large volumes of routine system activity, making full-graph learning both computationally expensive and difficult to correlate over long attack sequences. We present TGL-APT, an adaptive investigation framework built on the observation that attack-relevant information is non-uniformly distributed and often mediated by structurally influential or behaviorally distinctive entities, which we characterize as information-bottleneck nodes. TGL-APT combines three complementary components: (1) information-bottleneck-guided graph distillation that suppresses provenance redundancy while bounding structural distortion and preserving causal reachability; (2) adaptive temporal graph learning that continuously refines the core node set as node relevance evolves; and (3) cross-spatiotemporal attack fingerprint alignment that associates fragmented suspicious activities across different entities and time windows. Finally, causal expansion and stage characterization reconstruct coherent attack processes for investigation. Experiments on three DARPA E3 datasets show F1-scores of 95.7%, 90.9%, and 88.9%, while reducing training time, detection latency, and memory usage by approximately 39%, 33%, and 22%, respectively, compared with KAIROS. These results demonstrate that TGL-APT effectively balances detection performance, computational efficiency, and investigation capability for provenance-based APT analysis.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑