P3GNN: A Privacy-Preserving Provenance Graph-Based Model for Autonomous APT Detection in Software Defined Networking

Hedyeh Nazari, Abbas Yazdinejad, Ali Dehghantanha, Fattane Zarrinkalam, Gautam Srivastava · 2023

Software Defined Networking (SDN) has brought significant advancements in network management and programmability. However, this evolution has also heightened vulnerability to Advanced Persistent Threats (APTs), sophisticated and stealthy cyberattacks that current detection methods often fail to counter, especially in the face of zero-day exploits. A prevalent issue is the inadequacy of existing strategies to detect novel threats while addressing data privacy concerns in collaborative learning scenarios. This paper presents P3GNN, a novel model that synergizes Federated Learning (FL) with Graph Convolutional Networks (GCN) for autonomous and effective APT detection in SDN environments. P3GNN autonomously analyzes operational patterns within provenance graphs, identifying deviations indicative of security breaches. Its core feature is the integration of FL with homomorphic encryption, which fortifies data confidentiality and gradient integrity during collaborative learning. This approach addresses the critical challenge of data privacy in shared learning contexts. Key innovations of P3GNN include its ability to autonomously detect anomalies at the node level within provenance graphs, offering a detailed view of attack trajectories. Furthermore, the model's unsupervised learning capability enables it to independently identify zero-day attacks by learning standard operational patterns. Empirical evaluations using the DARPA TCE3 dataset demonstrate P3GNN's exceptional performance, achieving an accuracy of 0.93 and a low false positive rate of 0.06.

Read the paper · More papers on PaperTik