GraphWatch: A Novel Threat Hunting Approach for APT Activities based on Anomaly Detection
Robin Buchta, Carsten Kleiner, Felix Heine, Daniel Mahrenholz, Uwe Mönks, Henning Trsek · 2024
Cyber-physical systems (CPS) have become integral to critical infrastructure, making their security an important concern. Integrating information technology (IT) and operational technology (OT) in CPS has introduced complex security challenges. Established security measures often fall short in defending against sophisticated threats such as advanced persistent threats (APT), characterized by their stealth and persistence. This underscores the need for proactive security measures like threat hunting. Threat hunting combines automated and manual techniques to detect threats that bypass common security defenses. Threat hunting is based on hypothesis generation and investigation. In this context, our work presents GraphWatch, a novel approach to threat hunting in CPS. It leverages graph-based anomaly detection and graph neural networks (GNN) to model system behavior and detect deviations from normal activity, which could indicate a potential threat. This leads to a semi-automated hypothesis generation and investigation. The effectiveness of GraphWatch is evaluated using real-world demonstrators, digital twins, and public datasets. Future work aims to implement the concept and improve automation to increase the resilience of CPS against cyber threats and to incorporate automated responses in the long term.