This paper presents the problem of detecting complex, coordinated cyber-attacks at multiple intervals across enterprise networks. Traditional intrusion detection systems lack the ability to identify the ‘when’ and ‘where’ of attacks, resulting in an incomplete understanding of an attack’s propagation. Most current methodologies focus on the analysis of single, disconnected, and isolated events. This fundamentally limits their ability and effectiveness to understand or conceptualise complex attacks that develop or evolve over time. This paper presents a framework composed of GNNs that captures and analyses the activity of enterprises as dynamic interaction graphs, applying a temporal attention mechanism to focus and prioritise the analysis of high-risk, risky behavioural patterns. The framework is tested against the LAANL Logs and DARPA Transparent Computing cybersecurity datasets. The proposed adaptive temporal GNN achieves a 5% improvement over the strongest baseline (GAT) in detection accuracy, demonstrating its effectiveness in capturing multi-stage coordinated cyber-attacks. Furthermore, the framework provided a consistent and significant improvement in test environments that were imposed with noise. Lastly, the framework was also able to improve explainability through the analysis of the path of an attack’s propagation. This suggests that the results of the framework will validate the radical combination of the structural and the temporal elements of a complex cyber attack MODEL as a possible answer to the challenge of providing a simple, dynamic, and effective scalable solution to the detection of sophisticated cyber disasters in realistic and complex environments.
Suharsono et al. (Tue,) studied this question.