notesum.ai
Published at November 15Lateral Movement Detection via Time-aware Subgraph Classification on Authentication Logs
cs.CR
cs.AI
Released Date: November 15, 2024
Authors: Jiajun Zhou1, Jiacheng Yao1, Xuanze Chen1, Shanqing Yu1, Qi Xuan1, Xiaoniu Yang2
Aff.: 1Institute of Cyberspace Security, Zhejiang University of Technology, Hangzhou 310023, China; 2Science and Technology on Communication Information Security Control Laboratory, Jiaxing 314033, China

| Method | LANL | CERT | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Precision | Recall | F1 | Accuracy | AUC | Precision | Recall | F1 | Accuracy | AUC | |
| GCN | 57.420.774 | 63.732.076 | 59.240.458 | 94.560.959 | 76.330.736 | 50.700.270 | 70.492.342 | 46.034.028 | 80.8911.17 | 81.533.339 |
| GAT | 64.226.511 | 79.587.098 | 67.506.778 | 94.313.240 | 89.693.656 | 50.900.368 | 79.836.519 | 46.812.272 | 81.865.421 | 87.353.301 |
| GraphSAGE | 96.181.170 | 96.530.876 | 96.340.547 | 99.660.052 | 99.770.111 | 53.664.420 | 76.2213.96 | 52.243.378 | 92.305.397 | 90.474.891 |
| GCN-ts | 57.542.501 | 70.645.120 | 60.173.502 | 92.811.751 | 87.942.951 | 77.362.866 | 88.912.005 | 81.861.906 | 97.940.435 | 97.080.195 |
| GAT-ts | 87.3416.42 | 92.0911.27 | 86.1521.60 | 92.6619.50 | 97.832.878 | 75.908.216 | 83.305.774 | 77.985.691 | 97.411.258 | 96.091.467 |
| GraphSAGE-ts | 95.261.434 | 96.511.347 | 95.840.660 | 99.610.063 | 99.830.090 | 95.691.674 | 99.040.951 | 97.270.716 | 99.740.075 | 99.940.012 |
| LMTracker | 65.881.829 | 93.880.955 | 72.082.373 | 93.511.085 | 95.670.639 | 63.251.999 | 80.882.980 | 63.063.893 | 74.354.595 | 79.823.856 |
| Euler GCN-GRU | 50.260.013 | 94.820.520 | 50.370.033 | 99.390.035 | 99.040.187 | - | - | - | - | - |
| Euler GCN-LSTM | 50.280.012 | 94.330.278 | 50.410.027 | 99.420.023 | 98.600.263 | - | - | - | - | - |
| LMDetect(ours) | 98.200.819 | 99.890.194 | 99.030.467 | 99.910.044 | 99.990.004 | 97.460.506 | 99.460.468 | 98.430.324 | 99.870.026 | 99.990.004 |