Transform and graph neural network-based transverse movement detection method

By adopting a lateral movement detection method based on Transformer and graph neural network in network security, the limitations of the prior art when detecting lateral movement in enterprise networks are solved, and a more accurate and flexible detection effect is achieved.

CN120074925APending Publication Date: 2025-05-30BEIJING JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510225581.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing network security solutions have limitations in detecting lateral movements in enterprise networks and cannot effectively deal with dynamically changing network environments and complex malicious behaviors.

Method used

Using the lateral movement detection method based on Transformer and graph neural network, the authentication events in the enterprise network are converted into time series graph data through dynamic graph construction script processing, and the TGN and Transformer models are used for detection.

Benefits of technology

It realizes more accurate detection of lateral movement behavior, can maintain high detection rates in nodes/edges that have not been seen in the training stage, captures dynamic changes and long-term dependencies of the network, and improves the robustness and adaptability of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074925A_ABST
    Figure CN120074925A_ABST
Patent Text Reader

Abstract

The invention provides a Transform and graph neural network-based transverse movement detection method, which comprises the following steps of: obtaining to-be-detected log data of an enterprise host network, and carrying out dynamic graph construction script processing on the to-be-detected log data to obtain dynamic graph characteristics; inputting the dynamic graph features into a pre-trained transverse movement behavior detection model to obtain a detection result; wherein the transverse movement behavior detection model is a model based on Transform and a graph neural network. According to the method, the LM behavior can be detected more accurately, and the high detection rate can be kept even in nodes / edges which are not seen in the training stage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a lateral movement detection method based on Transformer and graph neural network. Background Art

[0002] Lateral movement (LM) is an important step in the implementation of attacks by advanced persistent threats (APT). However, existing network security solutions have limitations in detecting lateral movement in enterprise networks. These solutions usually rely on static graph representations and model training based on known normal behaviors, and are unable to effectively cope with dynamic network environments and complex malicious behaviors. Therefore, there is an urgent need for a lateral movement detection method that can accurately capture the attack characteristics of lateral movement and the dynamics of enterprise networks. Summary of the Invention

[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a lateral movement detection method based on Transformer and graph neural network.

[0004] To achieve the above purpose, the present invention adopts the following technical solutions.

[0005] In a first aspect, the present invention provides a lateral movement detection method based on Transformer and graph neural network, including:

[0006] Obtain the log data to be detected of the enterprise host network, and perform dynamic graph construction script processing on the log data to be detected to obtain dynamic graph features;

[0007] Input the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result;

[0008] Wherein, the lateral movement behavior detection model is a model based on Transformer and graph neural network.

[0009] Further, the lateral movement behavior detection model includes a TGN encoder, a Transformer encoder, and a decoder;

[0010] The step of inputting the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result includes:

[0011] Input the dynamic graph features into the TGN encoder to obtain a first graph embedding feature;

[0012] Input the first graph embedding feature into the Transformer encoder to obtain a second graph embedding feature;

[0013] Input the first graph embedding feature and the second graph embedding feature into a decoder to obtain a detection result.

[0014] Further, the dynamic graph feature includes a source graph feature and a target graph feature. The source graph feature includes the correspondence relationships between the target host and its source host, the target host and its user, and the source host and the user in each event. The target graph feature includes the correspondence relationships between the source host and its target host, the source host and its user, and the target host and the user in each event.

[0015] Further, the lateral movement behavior detection model is trained in the following manner:

[0016] Obtain the log data to be trained of the enterprise host network, and perform dynamic graph construction script processing on the log data to be trained to obtain dynamic graph features for training;

[0017] Merge the dynamic graph features for training with the verification time, user name, source host, target host, and event label in the log data to be trained to obtain training data;

[0018] Use the training data to train the lateral movement behavior detection model to obtain a trained lateral movement behavior detection model.

[0019] Further, the training data includes a timestamp, a source host, a target host, a label, a source graph feature, and a target graph feature.

[0020] Further, the lateral movement behavior detection model is a model based on Transformer and GCN or a model based on Transformer and GAT.

[0021] In a second aspect, the present invention also provides a lateral movement detection device based on Transformer and a graph neural network, including:

[0022] A data acquisition module, configured to acquire the log data to be detected of the enterprise host network, and perform dynamic graph construction script processing on the log data to be detected to obtain dynamic graph features;

[0023] A detection module, configured to input the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result;

[0024] Wherein, the lateral movement behavior detection model is a model based on Transformer and a graph neural network.

[0025] In a third aspect, the present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the above-mentioned method is implemented.

[0026] In a fourth aspect, the present invention further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above-mentioned method is implemented.

[0027] In a fifth aspect, the present invention further provides a computer program product including a computer program, and when the computer program is executed by a processor, the above-mentioned method is implemented.

[0028] Advantages of the present invention: The lateral movement detection method based on Transformer and graph neural network provided by the embodiments of the present invention can more accurately detect LM behaviors through dynamic graph construction script processing and detection of models based on Transformer and graph neural network, and can maintain a high detection rate even in nodes / edges not seen during the training phase. The present invention converts authentication events in an enterprise network into time series graph data through dynamic graph construction script processing, and these data can capture dynamic changes in the network, including newly emerging nodes (users, computers, servers) and connections between nodes (authentication events). The effects of this process are reflected in the following aspects: 1) Capturing network dynamics: By continuously monitoring authentication events, the script can update the network graph in real time, reflecting changes in the network structure, such as the addition of new nodes and the addition or disappearance of edges. 2) Feature extraction: During the script processing, not only the connections between nodes are recorded, but also graph features such as the in-degree and out-degree of nodes are calculated, and these features are crucial for understanding the dynamics of the network and identifying abnormal behavior patterns. 3) Time sensitivity: The dynamic graph construction script processing can maintain the time order of events, which is crucial for subsequent time series graph analysis and detection of lateral movement behaviors. Combining the advantages of TGN (Temporal Graph Networks) and Transformer models, the present invention can accurately capture the attack features of lateral movement for the following reasons: 1) Continuous-time dynamic graph: TGN is good at processing continuous-time dynamic graph data and can capture the changes of nodes over time and the complex temporal relationships between nodes, which is crucial for understanding dynamic behaviors in the network and detecting lateral movement behaviors. 2) Capturing long-term dependencies: The Transformer model can capture long-term dependencies between nodes through the self-attention mechanism, which is particularly effective for identifying hidden lateral movement behaviors because such behaviors may involve attack chains spanning long times and multiple nodes. 3) Generalization ability: The model combining TGN and Transformer can not only learn known attack patterns, but also generalize to unseen nodes and edges, improving the robustness and adaptability of the model in practical applications.

[0029] Additional aspects and advantages of the present invention will be given in part in the following description, will become apparent from the following description, or will be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0031] Figure 1 One of the schematic flowcharts of a lateral movement detection method based on Transformer and graph neural network provided for an embodiment of the present invention;

[0032] Figure 2 Another schematic flowchart of the lateral movement detection method based on Transformer and graph neural network provided for an embodiment of the present invention;

[0033] Figure 3 Schematic diagram of dynamic graph construction script processing provided for an embodiment of the present invention;

[0034] Figure 4 Another schematic flowchart of the lateral movement detection method based on Transformer and graph neural network provided for an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] The embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary only for explaining the present invention and should not be construed as limiting the present invention.

[0036] Those skilled in the art can understand that, unless specifically stated otherwise, the singular forms "a", "an", and "the" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present invention means the presence of features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or coupling. The phrase "and / or" used herein includes any unit and all combinations of one or more of the associated listed items.

[0037] Those skilled in the art can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the art to which the present invention pertains. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless defined as such here.

[0038] Current network security solutions, such as intrusion detection systems (IDS) and security information and event management (SIEM), usually rely on signature matching or anomaly detection algorithms. These methods are highly effective in detecting known attack patterns, but are limited in dealing with emerging and stealthy attack techniques, such as APT attacks. In recent years, graph neural network (GNN) technology has been used for network threat detection, but most of these methods are unable to effectively process dynamic graph data.

[0039] The following are the interpretations of the terms in the present invention:

[0040] Lateral movement (LM): Refers to the horizontal movement of a network attacker after successfully infiltrating a network in order to obtain more permissions.

[0041] Transformer: A deep learning model architecture based on self-attention mechanism, which achieves efficient feature learning and representation by processing each element in the sequence data in parallel.

[0042] Temporal graph neural network (TGN): A graph neural network that processes time series graph data.

[0043] For the convenience of understanding the embodiments of the present invention, the following will further explain with several specific embodiments in conjunction with the accompanying drawings, and each embodiment does not constitute a limitation to the embodiments of the present invention.

[0044] Embodiment 1

[0045] See Figures 1 to 4 , a lateral movement detection method based on Transformer and graph neural network, comprising the following steps:

[0046] S101. Obtain the log data to be detected of the enterprise host network, and perform dynamic graph construction script processing on the log data to be detected to obtain dynamic graph features.

[0047] Among them, the dynamic graph features include source graph features and target graph features. The source graph features include the corresponding relationships between the target host and its source host, the target host and its user, and the source host and the user in each event. The target graph features include the corresponding relationships between the source host and its target host, the source host and its user, and the target host and the user in each event. The dynamic graph features contain information such as the in-degree and out-degree features of nodes and the time stamps of edges (authentication events).

[0048] S102. Input the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result.

[0049] Among them, the lateral movement behavior detection model is a model based on Transformer and graph neural network. The lateral movement behavior detection model includes a TGN encoder, a Transformer encoder, and a decoder.

[0050] Specifically, S102 includes the following sub-steps:

[0051] Input the dynamic graph features into the TGN encoder to obtain the first graph embedding feature. That is, through the TGN encoder, node memory update is performed. Specifically, for each event at each time stamp, the TGN encoder updates the memory of the nodes participating in the event, and these memories contain the historical interaction information of the nodes. In addition, the TGN encoder also performs node embedding calculation. Specifically, using the updated memory and the current graph features, the TGN encoder calculates the embedding representation of each node, and these embedding representations capture the temporal and topological information of the nodes, so as to finally obtain the first graph embedding feature.

[0052] Input the first graph embedding feature into the Transformer encoder to obtain the second graph embedding feature. That is, through the Transformer encoder, sequence dependence learning is performed. Specifically, the Transformer encoder learns the sequence dependence relationship between node embeddings through the self-attention mechanism, and further refines the high-level representation of the nodes. Information aggregation is also performed through the Transformer encoder, that is, the Transformer encoder aggregates information from the L-hop neighborhood to provide more comprehensive context information for each node, so as to finally obtain the second graph embedding feature.

[0053] Input the first graph embedding feature and the second graph embedding feature into a decoder to obtain a detection result. That is, the decoder receives the graph embedding features output by two encoders, predicts whether there is a link of lateral movement behavior between nodes, calculates the probability that the event is a lateral movement behavior, and outputs the detection result.

[0054] Through the above process, the lateral movement behavior detection model can comprehensively consider the temporal behavior and topological structure of nodes, as well as the complex relationships between nodes, so as to achieve accurate detection of lateral movement behavior.

[0055] In addition, the lateral movement behavior detection model is trained in the following way:

[0056] Obtain the log data to be trained of the enterprise host network, and perform dynamic graph construction script processing on the log data to be trained to obtain the dynamic graph features for training.

[0057] Merge the dynamic graph features for training with the verification time, user name, source host, target host, and event label in the log data to be trained to obtain training data. Among them, the training data includes timestamp, source host, target host, label, source graph features, and target graph features.

[0058] Use the training data to train the lateral movement behavior detection model to obtain a trained lateral movement behavior detection model.

[0059] Specifically, in the dynamic graph construction script processing stage, the log data to be trained collected needs to include the verification time, user name, source host, target host fields of each authentication event and the label that distinguishes the event as benign or malicious. After the dynamic graph construction script processing, the processing results are six python dict-format files: InHostUserMap, InHostSrcMap, InHostUsrSrcMap, OutHostDstMap, OutHostUserMap, OutHostUsrDstMap. Each dict represents a part of the enterprise network temporal dynamic graph. The first three files are source graphs, which are the corresponding relationships between the target host and its source host, user, source host and user in each event. The last three files are target graphs, which are the corresponding relationships between the source host and its target host, user, target host and user in each event.

[0060] The graph feature calculation script calculates features for each part, including: In_Unique_Usr, In_Unique_Src, In_Unique_UsrSrc, and Out_Unique_Usr, Out_Unique_Dst, Out_Unique_UsrDst, Out_Day_Avg_Usr, Out_Day_Avg_Dst, Out_Day_Avg_UsrDst. Each event in the data will calculate the above features, and merge the above features with the verification time, user name, source host, target host, and event label in the log as the training data for the deep learning model. This training data is time series data and is stored in the form of {timestamp, source host, target host, label, source graph feature, target graph feature}, while the LM detection model is a model obtained by combining TGN (Temporal Graph Neural Network) and Transformer.

[0061] During the model training process, since the training data is time series data and in order to respond to the dynamics of the enterprise network, TGN (Temporal Graph Neural Network) is a more suitable choice than ordinary GNN (Graph Neural Network). However, TGN does not have an obvious focus on node embedding for temporal graphs. Therefore, it is considered to use Transformer with a multi-attention mechanism to dig out the key points in the long-term time series data and pay more attention to these key points. First, the encoder of TGN generates the node embeddings of the graph, and then these node embeddings are passed to the Transformer encoder to let Transformer further learn the sequential dependencies between the node embeddings.

[0062] After being processed by the Transformer encoder, the node embeddings pass through a decoder to detect whether the event is a lateral movement behavior. The encoder calculates the probability that the event is benign and the probability that the event is malicious, and judges the type of the event based on these two probabilities. The model adopts an inductive learning method, which means that the model can also have good generalization ability on behaviors not seen before. After training is completed, the model can be used to judge whether the behavior to be detected is a lateral movement behavior. Just provide the data to be detected with calculated features to the model, and the detection result can be obtained through the encoder-decoder pair.

[0063] In other embodiments of the present application, the lateral movement behavior detection model can be a model based on Transformer and GCN or a model based on Transformer and GAT, or a model based on Transformer and other graph neural networks.

[0064] The lateral movement detection method based on Transformer and graph neural network provided by the embodiments of the present invention can more accurately detect LM behavior through dynamic graph construction script processing and detection based on the models of Transformer and graph neural network, and can maintain a high detection rate even in nodes / edges not seen during the training phase. The present invention converts authentication events in an enterprise network into time series graph data through dynamic graph construction script processing, and these data can capture dynamic changes in the network, including newly emerging nodes (users, computers, servers) and connections between nodes (authentication events). The effects of this process are reflected in the following aspects: 1) Capturing network dynamics: By continuously monitoring authentication events, the script can update the network graph in real time, reflecting changes in the network structure, such as the addition of new nodes and the addition or disappearance of edges. 2) Feature extraction: During the script processing, not only the connections between nodes are recorded, but also graph features such as the in-degree and out-degree of nodes are calculated, and these features are crucial for understanding the dynamics of the network and identifying abnormal behavior patterns. 3) Time sensitivity: Dynamic graph construction script processing can maintain the time order of events, which is crucial for subsequent time series graph analysis and detection of lateral movement behavior. Combining the advantages of the TGN (Temporal Graph Networks) and Transformer models, the present invention can accurately capture the attack features of lateral movement for the following reasons: 1) Continuous-time dynamic graph: TGN is good at processing continuous-time dynamic graph data, and can capture the changes of nodes over time and the complex temporal relationships between nodes, which is crucial for understanding dynamic behaviors in the network and detecting lateral movement behaviors. 2) Capturing long-term dependencies: The Transformer model can capture long-term dependencies between nodes through the self-attention mechanism, which is particularly effective for identifying hidden lateral movement behaviors because such behaviors may involve attack chains spanning long times and multiple nodes. 3) Generalization ability: The model combining TGN and Transformer can not only learn known attack patterns, but also generalize to unseen nodes and edges, improving the robustness and adaptability of the model in practical applications.

[0065] Embodiment 2

[0066] Based on Embodiment 1, this Embodiment 2 provides a lateral movement detection device based on Transformer and graph neural network. The lateral movement detection device based on Transformer and graph neural network corresponds to the above-mentioned lateral movement detection method based on Transformer and graph neural network, and specifically includes:

[0067] A data acquisition module, configured to acquire the to-be-detected log data of the enterprise host network, perform dynamic graph construction script processing on the to-be-detected log data, and obtain dynamic graph features;

[0068] A detection module, configured to input the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result;

[0069] Wherein, the lateral movement behavior detection model is a model based on Transformer and graph neural network.

[0070] For specific details, refer to the description in the part of the lateral movement detection method based on Transformer and graph neural network, which will not be elaborated here.

[0071] Embodiment 3

[0072] Embodiment 3 of the present invention provides an electronic device, including a memory and a processor, the processor and the memory communicate with each other, the memory stores program instructions executable by the processor, and the processor calls the program instructions to execute the lateral movement detection method based on Transformer and graph neural network. The method includes the following process steps:

[0073] Obtain the log data to be detected of the enterprise host network, perform dynamic graph construction script processing on the log data to be detected to obtain dynamic graph features;

[0074] Input the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result;

[0075] Wherein, the lateral movement behavior detection model is a model based on Transformer and graph neural network.

[0076] Embodiment 4

[0077] Embodiment 4 of the present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the lateral movement detection method based on Transformer and graph neural network. The method includes the following process steps:

[0078] Obtain the log data to be detected of the enterprise host network, perform dynamic graph construction script processing on the log data to be detected to obtain dynamic graph features;

[0079] Input the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result;

[0080] Wherein, the lateral movement behavior detection model is a model based on Transformer and graph neural network.

[0081] Embodiment 5

[0082] Embodiment 5 of the present invention provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements a lateral movement detection method based on a Transformer and a graph neural network. The method includes the following process steps:

[0083] Obtain the log data to be detected of the enterprise host network, and perform dynamic graph construction script processing on the log data to be detected to obtain dynamic graph features;

[0084] Input the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result;

[0085] Wherein, the lateral movement behavior detection model is a model based on a Transformer and a graph neural network.

[0086] Those of ordinary skill in the art can understand that the drawings are only schematic diagrams of an embodiment, and the modules or processes in the drawings are not necessarily essential for implementing the present invention.

[0087] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for method or system embodiments, since they are basically similar to method embodiments, they are described relatively simply, and the relevant parts can be referred to the partial description of the method embodiments. The method and system embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement without creative efforts.

[0088] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A lateral movement detection method based on Transformer and graph neural network, characterized in that: include: Obtaining log data to be detected from the enterprise host network, performing dynamic graph construction script processing on the log data to be detected, and obtaining dynamic graph features; Inputting the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result; Among them, the lateral movement behavior detection model is a model based on Transformer and graph neural network.

2. The method according to claim 1, characterized in that The lateral movement behavior detection model includes a TGN encoder, a Transformer encoder and a decoder; The step of inputting the dynamic graph features into a pre-trained lateral movement behavior detection model to obtain a detection result includes: Inputting the dynamic graph feature into the TGN encoder to obtain a first graph embedding feature; Inputting the first graph embedding feature into a Transformer encoder to obtain a second graph embedding feature; The first image embedding feature and the second image embedding feature are input into a decoder to obtain a detection result.

3. The method according to claim 1, characterized in that The dynamic graph features include source graph features and target graph features. The source graph features include the corresponding relationships between the target host and its source host, the target host and its user, and the source host and the user in each event. The target graph features include the corresponding relationships between the source host and its target host, the source host and its user, and the target host and the user in each event.

4. The method according to claim 2, characterized in that: The lateral movement behavior detection model is trained in the following way: Obtaining the log data to be trained of the enterprise host network, and performing dynamic graph construction script processing on the log data to be trained to obtain dynamic graph features for training; Merging the training dynamic graph features with the verification time, user name, source host, target host, and event label in the log data to be trained to obtain training data; The lateral movement behavior detection model is trained using the training data to obtain a trained lateral movement behavior detection model.

5. The method according to claim 4, characterized in that The training data includes a timestamp, a source host, a target host, a label, a source graph feature, and a target graph feature.

6. The method according to claim 1, characterized in that The lateral movement behavior detection model is a model based on Transformer and GCN or a model based on Transformer and GAT.

7. A lateral movement detection device based on Transformer and graph neural network, characterized in that: include: A data acquisition module is used to acquire the log data to be detected of the enterprise host network, and perform dynamic graph construction script processing on the log data to be detected to obtain dynamic graph features; A detection module, used for inputting the dynamic image features into a pre-trained lateral movement behavior detection model to obtain a detection result; Among them, the lateral movement behavior detection model is a model based on Transformer and graph neural network.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that: A computer program is stored therein, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.