A Novel Approach for Identifying Lateral Movement Attacks Based on Network Embedding
Mingyi Chen, Yepeng Yao, Junrong Liu, Bo Jiang, Liya Su, Zhigang Lü · 2018
The growing targeted incidents constitute a permanent menace to internal security with more frequent data breach and service interruption events nowadays. Attackers move laterally and reside in the internal systems for accessing valuable information continuously. This paper proposed a novel approach based on network embedding synthesizing the information on hosts, traffics and correlations to forestall further loss under a deliberate attack. The approach begins with constructing a host communication graph with features extracted from the original data recorded in the internal network and the topology structures of the constructed network. Inspired by previous works, the approach uses a features aggregation learning method, that is composing the features on vertices and edges with neighbors' features to aggregate new composite features. Then the features are selected and learned iteratively. The ultimately selected features were reduced to lower dimension for training and used for the malicious host classification task. Besides, the approach can reemployment the classification results to optimize the dimensionality reduction. Compared with the state-of-the-art models and methods, the proposed approach is (i) flexible with multiple types of data and exchangeable methods, (ii) accurate in feature learning, selecting and extracting with the remarkably average accuracy of 99.9% and the average precision of 91.3%.