MESCAL: Malicious Login Detection Based on Heterogeneous Graph Embedding with Supervised Contrastive Learning

Weiqing Huang, Yangyang Zong, Zhixin Shi, Puzhuo Liu · 2023

Malicious logins via stolen credentials have become a primary threat in cybersecurity due to their stealthy nature. Recent malicious login detection methods based on graph learning techniques have made progress due to their ability to capture interconnected relationships among log entries. However, limited malicious samples pose a critical challenge to the detection performance of existing methods. In this paper, we propose MESCAL, a novel approach based on heterogeneous graph embedding with supervised contrastive learning to solve this challenge. Concretely, we construct authentication heterogeneous graphs to represent multiple and interconnected log events. Then, we pretrain a feature extractor with supervised contrastive learning to capture rich semantics on the graphs from limited malicious samples. Based on this, cost-sensitive learning is adopted to distinguish malicious logins on imbalanced data. Extensive evaluations show that the F1 score of MESCAL based on the imbalance dataset is 94.63%, which outperforms state-of-the-art approaches.

Read the paper · More papers on PaperTik