Jbeil: Temporal Graph-Based Inductive Learning to Infer Lateral Movement in Evolving Enterprise Networks
Joseph Khoury, Dorde Klisura, Hadi Zanddizari, Gonzalo De La Torre Parra, Peyman Najafirad, Elias Bou-Harb
摘要
Lateral Movement (LM) is one of the core stages of advanced persistent threats which continues to compromise the security posture of enterprise networks at large. Recent research work have employed Graph Neural Network (GNN) techniques to detect LM in intricate networks. Such approaches employ transductive graph learning, where fixed graphs with full nodes' visibility are employed in the training phase, along with ingesting benign data. These two assumptions in real-world setups (i) do not take into consideration the evolving nature of enterprise networks where dynamic features and connectivity prevail among hosts, users, virtualized environments, and applications, and (ii) hinder the effectiveness of detecting LM by solely training on normal data, especially given the evasive, stealthy, and benign-like behaviors of contemporary malicious maneuvers. Additionally, (iii) complex networks typically do not have the entire visibility of their run-time network processes, and if they do, they often fall short in dynamically tracking LM due to latency issues with passive data analysis.To this end, this paper proposes Jbeil, a data-driven framework for self-supervised deep learning on evolving networks represented as sequences of authentication timed events. The premise of the work lies in applying an encoder on a continuous-time evolving graph to produce the embedding of the visible graph nodes for each time epoch, and a decoder that leverages these embeddings to perform LM link prediction on unseen nodes. Additionally, we enclose a threat sample augmentation mechanism within Jbeil to ensure a well-informed notion on advanced LM attacks. We evaluate Jbeil using authentication timed events from the Los Alamos network which achieves an AUC score of 99.73% and a recall score of 99.25% in predicting LM paths, even when 30% of the nodes/edges are not present in the training phase. Additionally, we assess different realistic attack scenarios and demonstrate the potential of Jbeil in predicting LM paths with an AUC score of 99% in its inductive and transductive settings, out performing the state-of-the-art by a significant margin.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper4
- Entente: Cross-silo Intrusion Detection on Network Log Graphs with Federated LearningJiacen Xu, Chenang Li, Yu Zheng, Zhou LiNDSS 2026 · 被引用 3 次
- CAT: Can Trust be Predicted with Context-Awareness in Dynamic Heterogeneous Networks?Jie Wang, Zheng Yan, Jiahe Lan, Xuyan Li 等NDSS 2026 · 被引用 2 次
- CoLD: Collaborative Label Denoising Framework for Network Intrusion DetectionShuo Yang, Xinran Zheng, Jinze Li, Jinfeng Xu 等NDSS 2026 · 被引用 1 次
- A First-Principles Evaluation of Graph-Based Network Intrusion Detection SystemsRui Zhao, Wajih UI HassanCCS 2026
相关 Paper
- Euler: Detecting Network Lateral Movement via Scalable Temporal Graph Link PredictionIsaiah J. King, H. Howie HuangNDSS 2022
- How to Cover up Anomalous Accesses to Electronic Health RecordsXiaojun Xu, Qingying Hao, Zhuolin Yang, Bo Li 等USENIX Security 2023
- Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security AnalyticsJiacen Xu, Xiaokui Shu, Zhou LiS&P 2024 · 被引用 14 次
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 被引用 2 次
- Detecting Structurally Anomalous Logins Within Enterprise NetworksHossein Siadati, Nasir D. MemonCCS 2017 · 被引用 44 次
