Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security Analytics
Jiacen Xu, Xiaokui Shu, Zhou Li
摘要
Cyber-attacks have become increasingly sophisticated, which also drives the development of security analytics that produce countermeasures by mining organizational logs, e.g., network and authentication logs. Graph security analytics (GSA) that can model the complex communication patterns between users/hosts/processes have been extensively developed and deployed. Among the techniques that power GSAs, Unsupervised Network Representation Learning (UNRL) is gaining traction, which learns a latent graph representation, i.e., node embedding, and customizes it for different downstream tasks. Prominent advantages have been demonstrated by UNRL-based GSAs, as UNRL trains a detection model in an unsupervised way and exempts the model developers from the duty of feature engineering.In this paper, we revisit the designs of previous UNRL-based GSAs to understand how they perform in real-world settings. We found their performance is questionable on large-scale, noisy log datasets like LANL authentication dataset, and the main reason is that they follow the standard UNRL framework that trains a generic model in an attack-agnostic way. We argue that generic attack characteristics should be considered, and propose Argus, a UNRL-based GSA with new encoder and decoder designs. Argus is also designed to work on discrete temporal graphs (DTG) to exploit the graph temporal dynamics. Our evaluation of two large-scale datasets, LANL and OpTC, shows it can outperform the state-of-the-art approaches by a large margin.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal AnalyticsJiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou 等INFOCOM 2025 · 被引用 6 次
- Entente: Cross-silo Intrusion Detection on Network Log Graphs with Federated LearningJiacen Xu, Chenang Li, Yu Zheng, Zhou LiNDSS 2026 · 被引用 3 次
- CoLD: Collaborative Label Denoising Framework for Network Intrusion DetectionShuo Yang, Xinran Zheng, Jinze Li, Jinfeng Xu 等NDSS 2026 · 被引用 1 次
- A First-Principles Evaluation of Graph-Based Network Intrusion Detection SystemsRui Zhao, Wajih UI HassanCCS 2026
它引用的顶会 Paper33
- EvolveGCN: Evolving Graph Convolutional Networks for Dynamic GraphsAldo Pareja, Giacomo Domeniconi, Jie Chen, Tengfei Ma 等AAAI 2020 · 被引用 1,429 次
- Inductive representation learning on temporal graphsDa Xu, Chuanwei Ruan, Evren Körpeoglu, Sushant Kumar 等ICLR 2020 · 被引用 901 次
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 被引用 317 次
- Log2vec: A Heterogeneous Graph Embedding Based Approach for Detecting Cyber Threats within EnterpriseFucheng Liu, Yu Wen, Dongxue Zhang, Xihe Jiang 等CCS 2019 · 被引用 314 次
相关 Paper
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 被引用 2 次
- ARGUS: Context-Based Detection of Stealthy IoT Infiltration AttacksPhillip Rieger, Marco Chilese, Reham Mohamed, Markus Miettinen 等USENIX Security 2023
- Mitigating Anomaly Hallucination: A Model-Agnostic Framework for Unsupervised Anomaly Detection on Dynamic GraphsYingxuan Li, Yuanyuan Xu, Xuemin Lin, Ying ZhangKDD 2026
- CND-IDS: Continual Novelty Detection for Intrusion Detection SystemsSean Fuhrman, Onat Güngör, Tajana RosingDAC 2025 · 被引用 9 次
- Temporal SIR-GN: Efficient and Effective Structural Representation Learning for Temporal GraphsJanet Layne, Justin Carpenter, Edoardo Serra, Francesco GulloVLDB 2023 · 被引用 15 次
