An advanced persistent threat detection method and apparatus based on a graph attention model

CN117857200BActive Publication Date: 2026-05-26XIDIAN UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XIDIAN UNIV
Filing Date
2024-01-18
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing detection solutions are ineffective at detecting advanced persistent threats, especially those attacks that are highly covert and use zero-day vulnerabilities. Furthermore, existing methods are not sensitive enough to detect abnormal nodes and lack the ability to locate them.

Method used

An advanced persistent threat detection method based on a graph attention model is adopted. By constructing a data source graph, the hidden feature distribution of nodes is extracted from it, and multiple sub-models are used to calculate the probability of prediction type. The true type of the node is determined by combining the threshold.

Benefits of technology

It improves the detection efficiency of covert attacks, effectively identifies undiscovered zero-day vulnerabilities and new attack methods, reduces false alarms, and enhances the accuracy and robustness of the detection model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117857200B_ABST
    Figure CN117857200B_ABST
Patent Text Reader

Abstract

This invention provides an advanced persistent threat detection method and apparatus based on a graph attention model. It uses a graph attention network (GAT) to process node data in the source graph, and utilizes sub-models to output the predicted type probability of corresponding nodes. If a selected sub-model does not output a predicted type for a node, another selected sub-model obtains the predicted type probability of the node. Predicted types with a probability greater than a threshold are determined as the true type of the node. This invention introduces an attention mechanism into graph neural networks, which can learn and update node features using attention mechanisms. This allows for better extraction and learning of features from benign nodes. Furthermore, the sub-models of this invention are trained using benign nodes, eliminating the need to obtain information about abnormal nodes beforehand during the detection phase. It also achieves the same detection effect for undiscovered zero-day vulnerabilities, successfully detecting novel attack methods and zero-day vulnerabilities used by attackers.
Need to check novelty before this filing date? Find Prior Art