Abstract
This paper introduces Huntrace, a neural framework for APT detection through intelligent analysis of system provenance data. The framework features six core innovations: (1) Intelligent log-to-graph conversion automates the transformation of raw audit logs into structured heterogeneous provenance graphs using NLP-enhanced pattern recognition, resolving semantic fragmentation in multi-source system events. (2) Temporal Graph Network (TGN) models longitudinal attack behaviors by jointly encoding node interaction dynamics and time-decaying dependencies through memory-enhanced message passing, capturing APT-specific stealthy evolution patterns. (3) GAT-based anomaly focusing employs multi-head graph attention with contrastive learning to amplify subtle adversarial interactions while suppressing high-frequency benign activities, achieving noise-robust feature decoding. (4) K-means-driven forensic clustering hierarchically condenses high-attention subgraphs via modified inertia-adaptive clustering, enabling granular investigation of multi-stage attack footprints. (5) Filesystem-aware topology optimization streamlines graph construction through directory path flattening and inode-based deduplication, reducing redundant node-edge proliferation by 39 %. (6) Provenance-native graph database implements hybrid storage with edge-centric indexing and parallelized Gremlin query optimization, accelerating real-time subgraph retrieval by 5.7 ×. Evaluations demonstrate superior detection accuracy (F 1=0.925), average 1.7 % ~F-score gain over UNICORN, and 28.4 % LOFPR reduction, with 91.4 % node reconstruction accuracy and 8. 7 s temporal deviation in attack chains. Runtime optimizations enable 142 ms latency for 200 K -node graphs, 10.5 GB memory footprint, and 0.38 ~J / event energy efficiency (29 % lower than baseline), proving effectiveness in uncovering APT kill-chain semantics while maintaining interpretable forensic outputs.
| Original language | English |
|---|---|
| Title of host publication | Proceedings - 2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025 |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 102-109 |
| Number of pages | 8 |
| ISBN (Electronic) | 9798331579241 |
| DOIs | |
| State | Published - 2025 |
| Externally published | Yes |
| Event | 2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025 - Baoding, China Duration: 15 Aug 2025 → 17 Aug 2025 |
Publication series
| Name | Proceedings - 2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025 |
|---|
Conference
| Conference | 2025 IEEE 10th International Conference on Data Science in Cyberspace, DSC 2025 |
|---|---|
| Country/Territory | China |
| City | Baoding |
| Period | 15/08/25 → 17/08/25 |
UN SDGs
This output contributes to the following UN Sustainable Development Goals (SDGs)
-
SDG 7 Affordable and Clean Energy
Keywords
- APT Detection
- Forensic Clustering
- Graph Attention Mechanism
- Graph Database Optimization
- Log-Structured Storage
- Temporal Graph Network
Fingerprint
Dive into the research topics of 'Huntrace: Graph Neural Network Based APT Intrusion Detection on Homogeneous Provenance Graphs'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver