Skip to main navigation Skip to search Skip to main content

Huntrace: Graph Neural Network Based APT Intrusion Detection on Homogeneous Provenance Graphs

  • Yijing Zhu
  • , Jianye Yang*
  • , Zhaoquan Gu
  • *Corresponding author for this work
  • Guangzhou University
  • Harbin Institute of Technology Shenzhen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper introduces Huntrace, a neural framework for APT detection through intelligent analysis of system provenance data. The framework features six core innovations: (1) Intelligent log-to-graph conversion automates the transformation of raw audit logs into structured heterogeneous provenance graphs using NLP-enhanced pattern recognition, resolving semantic fragmentation in multi-source system events. (2) Temporal Graph Network (TGN) models longitudinal attack behaviors by jointly encoding node interaction dynamics and time-decaying dependencies through memory-enhanced message passing, capturing APT-specific stealthy evolution patterns. (3) GAT-based anomaly focusing employs multi-head graph attention with contrastive learning to amplify subtle adversarial interactions while suppressing high-frequency benign activities, achieving noise-robust feature decoding. (4) K-means-driven forensic clustering hierarchically condenses high-attention subgraphs via modified inertia-adaptive clustering, enabling granular investigation of multi-stage attack footprints. (5) Filesystem-aware topology optimization streamlines graph construction through directory path flattening and inode-based deduplication, reducing redundant node-edge proliferation by 39 %. (6) Provenance-native graph database implements hybrid storage with edge-centric indexing and parallelized Gremlin query optimization, accelerating real-time subgraph retrieval by 5.7 ×. Evaluations demonstrate superior detection accuracy (F 1=0.925), average 1.7 % ~F-score gain over UNICORN, and 28.4 % LOFPR reduction, with 91.4 % node reconstruction accuracy and 8. 7 s temporal deviation in attack chains. Runtime optimizations enable 142 ms latency for 200 K -node graphs, 10.5 GB memory footprint, and 0.38 ~J / event energy efficiency (29 % lower than baseline), proving effectiveness in uncovering APT kill-chain semantics while maintaining interpretable forensic outputs.

Original languageEnglish
Title of host publicationProceedings - 2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages102-109
Number of pages8
ISBN (Electronic)9798331579241
DOIs
StatePublished - 2025
Externally publishedYes
Event2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025 - Baoding, China
Duration: 15 Aug 202517 Aug 2025

Publication series

NameProceedings - 2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025

Conference

Conference2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025
Country/TerritoryChina
CityBaoding
Period15/08/2517/08/25

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 7 - Affordable and Clean Energy
    SDG 7 Affordable and Clean Energy

Keywords

  • APT Detection
  • Forensic Clustering
  • Graph Attention Mechanism
  • Graph Database Optimization
  • Log-Structured Storage
  • Temporal Graph Network

Fingerprint

Dive into the research topics of 'Huntrace: Graph Neural Network Based APT Intrusion Detection on Homogeneous Provenance Graphs'. Together they form a unique fingerprint.

Cite this