A Method and System for Fast Anomaly Detection and Attack Scenario Reconstruction Based on Source Graph

CN117411699BActive Publication Date: 2026-05-26SHANGHAI JIAOTONG UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANGHAI JIAOTONG UNIV
Filing Date
2023-10-27
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing source graph-based anomaly intrusion detection methods rely on the results of the training set, require prior knowledge or manual labeling, and have high computational complexity, making it difficult to quickly discover abnormal nodes in the source graph and reconstruct the attack scenario.

Method used

An unsupervised outlier detection algorithm combined with an empirical cumulative distribution function is used to mark abnormal nodes by calculating their abnormal scores. The properties of all nodes in the graph are trained using a heterogeneous graph neural network to achieve rapid detection and reconstruction of attack scenarios.

Benefits of technology

It significantly improves detection speed while consuming the same amount of computing resources, achieving unsupervised rapid detection and high-accuracy attack scenario reconstruction, without relying on prior attack knowledge.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117411699B_ABST
    Figure CN117411699B_ABST
Patent Text Reader

Abstract

This invention provides a method and system for rapid anomaly detection and attack scenario reconstruction based on a source graph, comprising: Step 1: Modeling the original log as a directed acyclic graph, using the subject and object of the event as nodes and system events as edges; Step 2: Employing an unsupervised outlier detection algorithm, using the in-degree of nodes according to edge categories as node features, and applying an empirical cumulative distribution function to calculate the outlier value of each node, marking nodes exceeding a threshold as anomalies; Step 3: Receiving a source graph with a small number of known node attributes, training a graph neural network model to perform a node classification task, judging the attributes of all nodes in the graph, and then discovering all nodes in the source graph associated with known anomalies. This invention, based on an empirical cumulative distribution function for anomaly detection and on a heterogeneous graph neural network model for attack scenario reconstruction, enables rapid detection of anomalies and identification of complete attack scenarios during reconstruction.
Need to check novelty before this filing date? Find Prior Art