Transverse movement attack detection method and system based on graph neural network

Through the detection method based on graph neural network, heterogeneous graphs are constructed and random walk sampling, node embedding learning and automatic encoder processing are carried out, which solves the problems of high resource consumption and insufficient flexibility of lateral movement attack detection in the prior art, and achieves efficient and accurate lateral movement attack detection.

CN120223401APending Publication Date: 2025-06-27GUANGZHOU UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510398919.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art has problems such as high resource consumption, high cost, insufficient flexibility and scalability, low detection effect, and insufficient performance in lateral mobile attack detection.

Method used

Using a graph neural network-based detection method, the combination of heterogeneous graphs, random walk sampling, node embedding learning and automatic encoder is used to achieve rapid and accurate identification of lateral movement attacks.

Benefits of technology

It improves the detection accuracy and speed of lateral movement attack behavior, reduces the resource consumption of detection, enhances the adaptability and scalability of the system, and realizes automated threat identification and response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223401A_ABST
    Figure CN120223401A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and provides a transverse movement attack detection method and system based on a graph neural network. The detection method comprises a data processing step, a heterogeneous graph construction step, a random walk sampling step, an anomaly identification step and a coping strategy generation step. The system comprises a graph construction module, a network analysis module and an attack prediction module. The lateral movement attack detection technology provided by the invention overcomes the defect of the prior art, improves the detection precision and speed of the lateral movement attack behavior, has strong adaptability and expandability, and can automatically identify and respond threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technology security, and particularly to a method and system for detecting lateral movement attacks based on graph neural networks. Background Art

[0002] With the rapid development of information technology, network informatization has become an important pillar for the operation of modern society. Various organizations such as enterprises and government agencies increasingly rely on complex network systems to handle daily operations and at the same time obtain a large amount of sensitive data. Therefore, along with network informatization comes the challenge of network security, especially the continuous evolution of the threat of network attacks, among which lateral movement attacks are particularly prominent.

[0003] A lateral movement attack refers to an attacker who, after successfully infiltrating a node in the network, continues to explore and penetrate other systems inside the network. This strategy enables the attacker to penetrate deep into the network to search for and steal valuable information or cause more extensive damage. Lateral movement attacks are common in advanced persistent threat (APT) and insider threat scenarios, where attackers may use the legitimate access rights and tools they have obtained to move secretly inside the network, greatly increasing the difficulty of detecting lateral movement attacks.

[0004] Currently, there are mainly three methods for detecting lateral movement attacks:

[0005] Rule-based detection methods detect lateral movement attacks by predefined security rules or the characteristics of known attack models. With the continuous evolution of the network environment and attack techniques, the rules need to be continuously updated and adjusted to match the latest security threats, which is not only time-consuming but also costly. Rule-based detection methods are often designed for specific threats or behavior patterns, which limits their flexibility and scalability. With the expansion of the network scale and the increase in complexity, rule-based detection methods are difficult to effectively handle changing attack scenarios and large amounts of data streams.

[0006] Anomaly-based detection methods detect lateral movement by building a normal model of network behavior and detecting behaviors that deviate significantly from this model. This method relies on threshold setting. It is difficult to determine what degree of behavior deviation is abnormal. Too loose a threshold may lead to missed reports, that is, real attack behaviors are not detected; while too strict a threshold may lead to an increase in the false alarm rate. Finding a suitable threshold setting for each scenario and network environment requires a large amount of debugging and adjustment, which is very resource-consuming. This method also has a strong dependence on historical data. If the historical data is insufficient or there are biases, the established normal behavior model is inaccurate, ultimately resulting in a decline in detection performance.

[0007] The method based on traffic analysis, network traffic analysis involves monitoring and analyzing network traffic data to facilitate the discovery of abnormal network connections or unusual data flow patterns, and can identify lateral movement behaviors. This method usually requires a large amount of computing resources and storage capabilities because it involves collecting, storing, and processing a large amount of network data. This places high requirements on hardware facilities. Especially in high-bandwidth or large-scale network environments, real-time analysis of network traffic may result in significant performance overhead. Moreover, with the popularization of communication security encryption, many traffic flows adopt SSL / TLS encryption, which poses a challenge to the method based on traffic analysis. The content of encrypted data is invisible, making it difficult to apply content-based analysis techniques.

[0008] Therefore, among the various lateral movement attack detection methods provided by the prior art, each has some problems, such as high resource consumption, high cost, insufficient flexibility and scalability, low detection effect, and insufficient performance. Summary of the Invention

[0009] Aiming at the problems existing in the prior lateral movement attack detection technology, the embodiments of the present application provide a lateral movement attack detection method based on a graph neural network to achieve fast and accurate identification of lateral movement attacks, reduce the consumption of lateral movement attack detection, improve the efficiency and performance of lateral movement attack identification, and achieve fast and accurate detection and identification.

[0010] The lateral movement attack detection method based on a graph neural network provided by the embodiments of the present application includes the following steps:

[0011] S100. Data processing step: Collect log data from network system security devices, and clean and standardize the log data to obtain standardized log data;

[0012] S200. Heterogeneous graph construction step: Use the standardized log data as the data input of the graph neural network, and establish a heterogeneous graph through the graph neural network. The heterogeneous graph includes nodes and connection edges. The nodes include user nodes, and the nodes also include at least two of host nodes, process nodes, and file nodes. The connection edges are operations between nodes;

[0013] S300. Random walk sampling step: Select at least one user node from the heterogeneous graph, adopt the random walk algorithm, and perform random walks according to the meta-path. When the preset conditions are met, stop the random walk sampling and output the node sequence visited during the random walk process;

[0014] S400, Node Embedding Learning Step: Use the skip-gram model to learn the node sequence obtained in the random walk sampling step, convert the nodes into low-dimensional vector representations, and capture the context and structural information of the nodes;

[0015] S500, Anomaly Recognition Step: Use the low-dimensional vector representation of the nodes as input and pass it to an autoencoder for learning and processing to distinguish between benign paths and abnormal movement paths; the autoencoder has at least two layers of neural networks;

[0016] S600, Generating Countermeasure Strategies Step: According to the characteristics of lateral movement attacks, output strategies for dealing with lateral movement attacks.

[0017] Preferably, the step S300 is specifically: starting from a node, perform a random walk according to the meta-path, and the probability of transferring from the i-th node to the i+1-th node is:

[0018] When (v i+1 ,v i )∈E, φ(v i+1 ) = t + 1,

[0019] Otherwise,

[0020] The node sequence is: S = [V1, V2,..., V k ,

[0021] vi represents the i-th node, vi+1 represents the i+1-th node, E represents the set of edges in the graph, that is, the connection relationship between nodes, φ represents the node type, φ(v i+1 ) = t + 1, and the current requirement is a node of type t + 1 for the next node, Starting from the current node vi, the set of adjacent nodes whose types belong to t + 1. Among them, the length of the random walk can be set or determined according to the length of the meta-path.

[0022] Preferably, the step S400 is specifically: by optimizing the following objective function N t (v) represents the context of node v, p(c t |v; θ) is the softmax function for different types of nodes, and the form is:

[0023] Preferably, in the step S500, the autoencoder includes an encoder and a decoder, and the process from the input layer to the hidden layer is:

[0024] h = f(x) = tanh(Wx + p)

[0025] The process from the hidden layer to the output layer is as follows:

[0026]

[0027] Among them, x represents the input path vector, h is the hidden layer, y is the reconstructed output, Wx and Wh are the weight matrices of the encoder and decoder respectively, and p and q correspond to the bias vectors.

[0028] After the input vector is reconstructed by the autoencoder, By calculating the reconstruction error

[0029] It is used as the anomaly score, and a high anomaly score represents a malicious lateral movement behavior.

[0030] Preferably, after obtaining the input vector after node embedding, the weights in the network need to be initialized before training the autoencoder:

[0031]

[0032] Then, two encodings are performed:

[0033] h1 = f(x) = tanh(W1x + p1),

[0034] h2 = f(h1) = tanh(W2h1 + p2);

[0035] Then, two decodings are performed:

[0036]

[0037] Preferably, it further includes:

[0038] S700. Backpropagation and weight update: Using the mean square error to evaluate the difference between the output and the expected output, and using the backpropagation algorithm to calculate the partial derivative of the function with respect to each weight, and these partial derivatives indicate how to adjust the weights to reduce the loss

[0039]

[0040] For the same purpose, the embodiment of the present application also provides a lateral movement attack detection system based on a graph neural network, including:

[0041] A graph construction module, where the image construction module includes a data processing sub-module and a heterogeneous graph construction sub-module: the data processing sub-module is used to collect log data from network system security devices, clean and standardize the log data to obtain standardized log data; the heterogeneous graph construction module is used to use the standardized log data as the data input of the graph neural network, and establish a heterogeneous graph through the graph neural network. The heterogeneous graph includes nodes and connection edges. The nodes include user nodes, and the nodes also include at least two of host nodes, process nodes, and file nodes. The connection edges are operations between nodes.

[0042] A network analysis module, where the network analysis module includes a random walk sampling sub-module and a node embedding learning sub-module: the random walk sampling sub-module is used to select at least one user node from the heterogeneous graph, adopt the random walk algorithm, and perform random walk according to the meta-path. When the preset conditions are met, stop the random walk sampling and output the node sequence visited during the random walk process; the node embedding sub-module uses the skip-gram model to learn the node sequence obtained in the random walk sampling step, convert the nodes into low-dimensional vector representations, and capture the context and structure information of the nodes.

[0043] An attack prediction module, including an autoencoder and a response strategy sub-module: the autoencoder includes at least two layers of neural networks, which are used to take the low-dimensional vector representation of the nodes as input and automatically learn to distinguish between benign paths and abnormal movement paths; the response strategy sub-module is used to output strategies for dealing with lateral movement attacks according to the characteristics of lateral movement attacks.

[0044] For the same purpose, an embodiment of the present application also provides an electronic device, including a memory and a processor,

[0045] The memory stores computer-executable instructions;

[0046] The processor executes the computer-executable instructions stored in the memory to implement a method for detecting lateral movement attacks based on a graph neural network.

[0047] For the same purpose, an embodiment of the present application also provides a computer-readable storage medium, where computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement a method for detecting lateral movement attacks based on a graph neural network.

[0048] For the same purpose, an embodiment of the present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements a method for detecting lateral movement attacks based on a graph neural network.

[0049] The lateral movement attack detection method, detection system, electronic device, computer-readable storage medium, and computer program product based on graph neural network provided by this application have the following beneficial technical effects compared with the lateral movement attack detection technology provided by the prior art:

[0050] 1. Improve the detection accuracy and speed of lateral movement attack behaviors. By using graph neural networks to process data structures that represent complex relationships and dependencies, such as various entities (users, devices, application programs, etc.) in the network environment and the interactions between these entities, graph neural networks can capture the direct and indirect relationships between these entities, which is crucial for understanding and detecting lateral movement attacks, providing support for more accurately identifying abnormal behaviors and patterns related to lateral movement, and reducing false positives and false negatives. And ensure that the detection system can operate under real-time or near-real-time conditions to ensure that network threats can be discovered and processed immediately.

[0051] 2. Strong adaptability and scalability. Graph neural networks can automatically learn from new data and adjust the detection strategy, enabling the system to effectively respond to security threats in different scales and types of network environments.

[0052] 3. Automatic threat identification and response. By constructing a global view of network entities and operations, this method can capture complex relationships and potential attack paths, analyze and obtain more real internal network behavior dynamics. Graph neural networks enable the system to automatically identify atypical behaviors, such as abnormal access attempts and potential data leakage activities, by learning and analyzing the structures and patterns in the network topology. Automatically identify lateral movement behaviors and trigger corresponding security response measures, reducing the need for manual intervention and improving the response speed and efficiency of network defense. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0054] Figure 1 It is a schematic structural diagram of a lateral movement attack detection system based on graph neural network in an embodiment of this application;

[0055] Figure 2 It is a schematic diagram of an example of a lateral movement attack detection method based on graph neural network in an embodiment of this application;

[0056] Figure 3 It is a schematic flowchart of a lateral movement attack detection method based on graph neural network in an embodiment of this application. Detailed implementation manners

[0057] In the following, only some exemplary embodiments are simply described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present invention. Therefore, the drawings and the description are considered to be exemplary in nature rather than restrictive.

[0058] It should be noted that terms such as "first", "second", "symmetric", "array", etc. are only used for the purpose of distinguishing descriptions and position descriptions, and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "symmetric", etc. can explicitly or implicitly include one or more of such features; similarly, when certain features are not limited in quantity by words such as "two", "three", etc., it should be noted that such features also belong to explicitly or implicitly including one or more feature quantities;

[0059] In the present invention, unless otherwise clearly specified and defined, terms such as "installation", "connection", "fixation", etc. should be understood in a broad sense; for example, it can be a fixed connection, a detachable connection, or an integrally formed one; it can be a mechanical connection, a direct connection, a welding connection, or an indirect connection through an intermediate medium, and can be the communication inside two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood in combination with the drawings of the specification and specific circumstances.

[0060] The embodiments of the present invention will be described in detail below with reference to the drawings.

[0061] As Figure 1 shown, the lateral movement attack detection system based on a graph neural network provided by the embodiment of the present application includes:

[0062] A graph construction module, the image construction module includes a data processing sub-module and a heterogeneous graph construction sub-module: the data processing sub-module is used to collect log data from network system security devices, and perform cleaning and standardization processing on the log data to obtain standardized log data; the heterogeneous graph construction module is used to use the standardized log data as the data input of the graph neural network, and establish a heterogeneous graph through the graph neural network. The heterogeneous graph includes nodes and connection edges. The nodes include user nodes, and the nodes also include at least two of host nodes, process nodes, and file nodes. The connection edges are operations between nodes;

[0063] A network analysis module, which includes a random walk sampling sub-module and a node embedding learning sub-module (also called a node embedding sub-module based on the Skip-gram model): The random walk sampling sub-module is used to select at least one user node from the heterogeneous graph, adopt the random walk algorithm, perform random walk according to the meta-path, stop the random walk sampling when the preset condition is satisfied, and output the node sequence visited during the random walk process; The node embedding sub-module uses the skip-gram model to learn the node sequence obtained in the random walk sampling step, converts the nodes into low-dimensional vector representations, and captures the context and structure information of the nodes;

[0064] An attack prediction module, including an autoencoder and a response strategy sub-module: The autoencoder includes at least two layers of neural networks, which are used to take the low-dimensional vector representation of the nodes as input and automatically learn to distinguish between benign paths and abnormal movement paths; The response strategy sub-module is used to output a strategy for dealing with lateral movement attacks according to the characteristics of lateral movement attacks.

[0065] The lateral movement attack detection system based on graph neural network provided by this application designs a new network and program log processing method, realizing high-efficiency, high-precision, and low-false-alarm lateral movement attack detection, and meeting the lateral movement attack detection requirements in a dynamically changing network environment. This system consists of three modules. Among them, the graph construction module collects and standardizes the data, removes the missing and obviously incorrect log information, and converts the processed data into a heterogeneous graph to maximize the retention of the original log information. The graph neural network analysis module performs random sampling on the heterogeneous graph, which can improve the processing speed of the system while maintaining the correct rate. The attack prediction module includes two parts: abnormal pattern recognition and response mitigation. This module is responsible for automatically identifying and responding to the internal behavior of the system, further reducing human intervention and improving the intelligent level of the system.

[0066] Suppose a large enterprise has deployed a network information system. This enterprise has multiple data centers and office locations, and the network contains thousands of devices and servers. Recently, this enterprise has suffered multiple targeted network attacks. The attacker obtained the credentials of an employee through a phishing email, and then tried to move laterally in the internal network to find more valuable targets. The lateral movement behavior of the attacker will be recorded in the system's log file, and this recorded information will be used to train the recognition model, which can accurately identify the lateral movement behavior and give a response.

[0067] If this large enterprise deploys the lateral movement attack detection system based on graph neural network of this application in its network to protect its distributed IT infrastructure. The specific implementation example of the lateral movement detection system based on graph neural network for lateral movement detection is as Figure 2As shown below. The specific process applied by the present invention in this case Figure 3 As shown, including:

[0068] S100, data processing step: Collect log data from network system security devices, and clean and standardize the log data to obtain standardized log data.

[0069] Among them, network system security devices include IDS / IPS systems, firewalls, system monitoring tools, etc. Log data such as network logs, system logs, application logs, and security event report logs are collected from network system security devices. The log data is cleaned to remove noise data, redundant data, irrelevant information, and incomplete recorded data, and correct data with format errors. Key features are extracted from the cleaned data, including user unique identifiers, IP addresses, timestamps, and operation types. Finally, through standardization processing, the data is converted into a unified format, unified timestamp format, and encoding conversion. The log data is converted into a standardized tuple <time, source computer, source user, target computer, target user, event type, event attribute>.

[0070] S200, heterogeneous graph construction step: Use the standardized log data as the data input of the graph neural network, and establish a heterogeneous graph through the graph neural network. The heterogeneous graph includes nodes and connection edges. The nodes include user nodes, and the nodes also include at least two of host nodes, process nodes, and file nodes. The connection edges are operations between nodes.

[0071] In an information network system, users are the main body, and the objects of their operating systems are divided into three types, namely hosts, files, and processes. Operations on hosts include login, logout, etc.; operations on files include view, open, execute, etc.; operations on corresponding processes include create, delete, etc. The graph neural network identifies entities such as devices, users, and programs based on features, and each entity is used as a node in the graph. Connection edges are created based on the interactions between entities (login, use, create process). Therefore, the constructed heterogeneous graph contains different objects such as hosts, users, processes, and files as nodes, and operations such as login, logout, create, and open as the connection edges of the graph, and the nodes and connection edges are structured and stored using a graph database or framework tool, retaining all attributes. The purpose of this method is to integrate multi-source data, including user, device, process, and file entities, as well as their interaction behaviors. Compared with traditional log graphs, heterogeneous graphs contain more detailed information and the relationships between objects are more intuitive.

[0072] S300, random walk sampling step: Select at least one user node from the heterogeneous graph, adopt the random walk algorithm, perform random walk according to the meta-path, stop the random walk sampling when the preset condition is met, and output the node sequence visited during the random walk process.

[0073] Select one or more nodes from the heterogeneous graph as the starting points of random walks. According to the walk selection rules formulated by the administrator, non-uniform selection is performed based on specific attributes (such as node weights or node types). When a certain number of steps are reached or a sufficient number of nodes are covered, the sequence of nodes visited during the walk is output for subsequent analysis and model training. Compared with other graph sampling methods, random walk sampling has better coverage when the graph structure is complex or irregular. For a dynamically changing graph, random walk sampling can also adaptively update the graph state without reconstructing the sampling process from scratch. The random walk algorithm is used to sample subgraphs from a large-scale graph on a heterogeneous graph, and the random walk algorithm is used to ensure that the sampled subgraphs are balanced in terms of categories and features, avoiding training bias.

[0074] Among them, when the system starts the walk process in parallel from multiple starting points, multiple paths are correspondingly generated, and each path represents a potential lateral movement behavior pattern. This method can improve the coverage of path generation and the success rate of attack detection. The described walk selection rules are, for example: set a meta-path P = User → Host → Process, indicating that it is desired to start from the user, find the hosts it accesses, and then find the processes running on the hosts, so as to capture the attack behavior chain. According to the previous probability transition formula of random walks, matching nodes are selected, and if there are no qualified nodes, the path generation is terminated. For the number of steps or covering a sufficient number of nodes, by default, random walks will automatically stop according to the state transition equation. However, to ensure the efficiency of the method, when the graph scale is too large, the path coverage hop count can also be specified, for example, stop after 50 transfers.

[0075] Processing the heterogeneous graph constructed from all logs is very large, so it is necessary to simplify the heterogeneous graph. The present invention adopts the method of random walk sampling, which can ensure that within the range of acceptable information loss, the original graph information is retained to the greatest extent. Starting from the user nodes in the graph, random walks are performed according to the meta-path, and the probability of transferring from the i-th node to the i + 1-th node is: When (v i+1 , v i ) ∈ E, φ(v i+1 ) = t + 1, otherwise vi represents the i-th node, vi+1 represents the i + 1-th node, E represents the set of edges in the graph, that is, the connection relationship between nodes, φ represents the node type, φ(v i+1 ) = t + 1, and currently it is required that the next node is of type t + 1, Starting from node vi, the set of all adjacent nodes whose type belongs to t+1. The length n of the random walk sampling is predefined by the user, otherwise it is the same as the length of the meta-path. Finally, the walk sequence is obtained: S = [V1, V2,..., V k .

[0076] This formula defines a random walk rule with type constraints:

[0077] 1. Only transfer along node types that match the source path during the journey;

[0078] 2. When there is an edge and it meets the target type, select a qualified neighbor node;

[0079] 3. If the edge does not exist or the type does not match, do not transfer.

[0080] S400. Node embedding learning step: Use the skip-gram model to learn the node sequence obtained in the random walk sampling step, convert the nodes into low-dimensional vector representations, and capture the context and structure information of the nodes.

[0081] Use the Skip-Gram model to learn the randomly sampled subgraph, convert the nodes into low-dimensional vector representations, and capture the context and structure information of the nodes. Apply the skip-gram model to learn the random walk sequence. The input of the model is the current state of the target node, and the output is the probability distribution of the predicted context nodes. The model is trained by maximizing the proximity between the target node and its context nodes in the vector space. And use the softmax technique to optimize the training process. After training, the embedding vectors of the nodes can be extracted from the hidden layer weights of the skip-gram model. Such as extracting the embedding vectors of each node from the weight matrix between the input layer and the hidden layer. The weight matrix |V| is the number of nodes in the journey, d is the embedding dimension, and the embedding representation of node vi is e(v i ) = W [i] . This embedding vector encodes the structural position and context information of the node in the graph, and can be used for attack path modeling and classification in the future. These vectors encode the position and context information of the nodes in the heterogeneous graph. The Skip-Gram model retains more comprehensive local structure information compared to other node embedding models, and the window mechanism of the skip-gram model can control the context range considered during the learning process, with stronger flexibility and adaptability.

[0082] Use the Skip-Gram algorithm to generate node embeddings, simply expressed as optimizing the following objective function N t (v) represents the context of node v, p(c tsoftmax(v; θ) is the softmax function for different types of nodes, in the form of:

[0083]

[0084] S500. Anomaly recognition step: Use the low-dimensional vector representation of the nodes as input to the autoencoder for learning and processing to distinguish between benign paths and abnormal movement paths; the autoencoder has at least two layers of neural networks.

[0085] Use the autoencoder of the multi-layer neural network to distinguish between benign paths and abnormal lateral movement paths. Among them, the benign path refers to the normal movement sequence, and the abnormal path refers to the path that includes malicious attempt behaviors such as scanning and sniffing the system during the movement, as well as abnormal behaviors such as starting a malicious process on a host, destroying the main process of the system, or killing the daemon process of the host. The autoencoder includes an encoder and a decoder. The two processes from the input layer to the hidden layer and from the hidden layer to the output layer are as follows:

[0086] h = f(x) = tanh(Wx + p)

[0087]

[0088] where x represents the input path vector, h is the hidden layer, y is the reconstructed output, Wx and Wh are the weight matrices of the encoder and decoder respectively, and p and q correspond to the bias vectors.

[0089] The system learns the distribution characteristics of the paths by minimizing the error between the original input and the reconstructed output, and determines whether the path is abnormal through the reconstruction error.

[0090] After the autoencoder reconstructs the input vector (i.e., the node embedding vector generated by random walk), By calculating the reconstruction error As the anomaly score, a high anomaly score indicates that there is an obvious difference between the input data and the normal data distribution learned by the autoencoder, thereby distinguishing malicious lateral movement behaviors. The method of using the autoencoder to identify abnormal lateral movement behaviors does not require data marking, reducing the workload of data processing. The autoencoder has good generalization ability. When encountering a new type of lateral movement attack that has never been seen before, it may also be identified and detected because of its difference from the normal mode. The autoencoder model can adjust the model complexity according to needs, with better flexibility and scalability.

[0091] The low-dimensional vector representation of the nodes is used as input to the autoencoder for learning and processing to obtain the reconstruction result. The mean square error is used to evaluate the difference between the output and the expected output. The greater the difference, the greater the possibility of a lateral movement attack.

[0092] Autoencoder processing flow: After obtaining the input vector with node embeddings, the weights in the network need to be initialized before training the autoencoder. Then, two encoding and decoding processes are carried out: h1 = f(x) = tanh(W1x + p1), h2 = f(h1) = tanh(W2h1 + p2).

[0093] S600, Step of generating countermeasures: According to the characteristics of lateral movement attacks, output the strategies for dealing with lateral movement attacks.

[0094] Compare the final processed result with the input to obtain the reconstruction error as the final anomaly score. The larger the error, the more obvious the abnormal performance, and it is more likely to be a lateral movement behavior. Once a potential lateral movement attack is detected, corresponding security response measures will be formulated and executed. This includes automatically isolating the affected system nodes, restricting the access rights of suspicious accounts, adjusting the network access control policy, or triggering a security alert to notify the security operation and maintenance team for further analysis and intervention.

[0095] S700, Backpropagation and weight update: Use the mean squared error to evaluate the difference between the output and the expected output, and use the backpropagation algorithm to calculate the partial derivatives of the function with respect to each weight. These partial derivatives indicate how to adjust the weights to reduce the loss.

[0096]

[0097] The lateral movement attack detection system and method based on graph neural network provided by the embodiments of the present application can deeply learn and simulate complex entities (such as users, devices, processes, etc.) in the network and their interactions. Through random walks, the system can capture the direct and indirect relationships between nodes, and the Skip-gram algorithm further extracts the patterns in these relationships and converts them into node embedding vectors. These vectors capture the structural context of the nodes in the graph, enabling the system to not only understand the behavior of individual entities but also understand how entities interact with each other, realizing in-depth learning of complex relationships and structures.

[0098] The introduction of the autoencoder enhances the system's ability to identify abnormal behaviors. By comparing the reconstruction error of the input data, the autoencoder can effectively identify behaviors that are significantly different from the learned normal patterns. In the scenario of lateral movement attacks, this means that even subtle abnormal signals, such as atypical user-to-device access, can be detected, achieving highly sensitive detection of abnormal behaviors.

[0099] The framework of the graph neural network provides a high degree of scalability and adaptability. As the network scale grows or new devices and users are added, the graph structure can be dynamically updated, and at the same time, the model can be retrained to adapt to new data patterns. In addition, since the graph neural network can handle heterogeneous data, this enables the system to integrate various types of network behavior data, such as log files, transaction records, etc., further enhancing the detection ability. Achieving high scalability and high adaptability.

[0100] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various changes or substitutions thereof, and these should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claimed rights.

Claims

1. A lateral movement attack detection method based on graph neural network, characterized in that: The following steps are involved: S100, data processing step: collecting log data from network system security devices, and cleaning and standardizing the log data to obtain standardized log data; S200, heterogeneous graph construction step: using the standardized log data as data input of the graph neural network, and establishing a heterogeneous graph through the graph neural network, wherein the heterogeneous graph includes nodes and connection edges, wherein the nodes include user nodes, and the nodes also include at least two types of nodes selected from host nodes, process nodes, and file nodes, and the connection edges are operations between nodes; S300, random walk sampling step: selecting at least one user node from the heterogeneous graph, using a random walk algorithm, performing random walk according to a meta-path, stopping random walk sampling when a preset condition is met, and outputting a node sequence visited during the random walk; S400, node embedding learning step: use the skip-gram model to learn the node sequence obtained in the random walk sampling step, convert the node into a low-dimensional vector representation, and capture the context and structure information of the node; S500, abnormality identification step: passing the low-dimensional vector representation of the node as input to the autoencoder for learning processing to distinguish between benign paths and abnormal movement paths; the autoencoder has a neural network with at least two layers; S600, generating a response strategy step: outputting a strategy for responding to a lateral movement attack according to the characteristics of the lateral movement attack.

2. The method according to claim 1, characterized in that The step S300 is specifically as follows: starting from the node, performing random walk according to the meta-path, the probability of transferring from the i-th node to the i+1-th node is: When (v i+1 ,v i )∈E,φ(v i+1 )=t+1, otherwise, The node sequence is: S = [V1, V2, ..., V k ], vi represents the i-th node, vi+1 represents the i+1-th node, E represents the set of edges in the graph, that is, the connection relationship between nodes, φ represents the node type, φ(v i+1) = t+1, the current requirement is that the next node is of type t+1. Starting from the current node vi, the set of nodes of type t+1 among all adjacent nodes; The length of the random walk can be set or determined according to the length of the meta-path.

3. The method according to claim 1, characterized in that The step S400 is specifically: by optimizing the following objective function N t (v) represents the context of node v, p(c t |v; θ) is the softmax function of different types of nodes, in the form of:

4. The method according to claim 1, characterized in that In step S500, the autoencoder includes an encoder and a decoder, and the process from the input layer to the hidden layer is: h=f(x)=tanh(Wx+p) The process from hidden layer to output layer is: Where x represents the input path vector, h is the hidden layer, y is the reconstructed output, Wx and Wh are the weight matrices of the encoder and decoder respectively, and p and q correspond to the bias vectors; After the autoencoder reconstructs the input vector, By calculating the reconstruction error Treat it as an anomaly score, and a high anomaly score indicates malicious lateral movement behavior.

5. The method according to claim 4, characterized in that After getting the input vector after node embedding, the weights in the network need to be initialized before training the autoencoder: Then encode twice: h1=f(x)=tanh(W1x+p1), h2=f(h1)=tanh(W2h1+p2); Decode twice more:

6. The method according to any one of claims 1 to 5, characterized in that: Also includes: S700, Back Propagation and Weight Update: Using Mean Squared Error To evaluate the difference between the output and the expected output, the back-propagation algorithm is used to calculate the partial derivatives of the function with respect to each weight. These partial derivatives indicate how to adjust the weights to reduce the loss.

7. A lateral movement attack detection system based on graph neural network, characterized in that: include: A graph construction module, the graph construction module includes a data processing submodule and a heterogeneous graph construction submodule: the data processing submodule is used to collect log data from network system security devices, and clean and standardize the log data to obtain standardized log data; the heterogeneous graph construction module is used to use the standardized log data as data input of the graph neural network, and establish a heterogeneous graph through the graph neural network, the heterogeneous graph includes nodes and connection edges, the nodes include user nodes, the nodes also include at least two types of nodes among host nodes, process nodes, and file nodes, and the connection edges are operations between nodes; A network analysis module, the network analysis module includes a random walk sampling submodule and a node embedding learning submodule: the random walk sampling submodule is used to select at least one user node from the heterogeneous graph, adopt a random walk algorithm, perform random walk according to the meta-path, stop random walk sampling when a preset condition is met, and output the node sequence visited during the random walk; the node embedding submodule uses a skip-gram model to learn the node sequence obtained in the random walk sampling step, convert the node into a low-dimensional vector representation, and capture the context and structural information of the node; The attack prediction module includes an autoencoder and a response strategy submodule: the autoencoder includes at least two layers of neural networks, which are used to take the low-dimensional vector representation of the node as input and automatically learn to distinguish between benign paths and abnormal movement paths; the response strategy submodule is used to output a strategy for responding to lateral movement attacks based on the characteristics of lateral movement attacks.

8. An electronic device, characterized in that: including memory and processor, The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the lateral movement attack detection method based on graph neural network as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the lateral movement attack detection method based on a graph neural network as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, which, when executed by a processor, implements the lateral movement attack detection method based on graph neural network as described in any one of claims 1 to 6.