Attack Path Extraction based on VGAE and DBSCAN
Ziang Lu, Lu Chen, Yongbo Li, Guangxin Guo, Tengyan Wang · 2024
Mining and analyzing potential attack paths in networks based on alarm information can provide references for accurate and effective network defense measures. However, current research lacks thorough extraction and integration of deep features from alarm information. In this work, we propose APE-VD, an attack path extraction model based on VGAE and DBSCAN. It involves constructing network attack graphs based on host connectivity information and alarm types. Additionally, it creates temporal attack graphs by combining alarm data from different time slices with flow relationships. Using variational autoencoders, the temporal attack graphs are reduced in dimensionality to obtain alarm flow features. DBSCAN clustering is utilized to mine outlier nodes. To enhance clustering accuracy and robustness, second-order temporal risk features are extracted based on outlier nodes as prior information. Further, variational autoencoders and DBSCAN clustering are applied again. After filtering based on risk thresholds, forward and backward retrieval of nodes is conducted to derive attack paths. Simulation results on widely used log datasets demonstrate that APE-VD can efficiently uncover attack paths within limited computational complexity, aiding in reconstructing attack scenarios.