An Empirical Study on Analyzing the Evidence-Based Method in Attack Path Detection

Mukesh Yadav, Peter J. Hawrylak · 2024

Predicting the attack path based on the attacker’s real-time activities are crucial to simultaneously improving the system’s security. Our study investigated models that include evidence in their analysis and models that do not incorporate evidence for analyzing the attack path. For evidence-based models, we implement the Viterbi algorithm and Graph Neural Network (GNN) autoencoder with a transformer network. The genetic algorithm and PageRank algorithms were implemented that do not use evidence as input to the model. After experiments were conducted, the evidence-based model performed better than the model that does not use evidence. The experiment was conducted on 200 simulated attack graphs. The evidence-based model using a GNN-Transformer network performed better than other methods used in the experiment.

Read the paper · More papers on PaperTik