KGNN: Combining KAN Networks and Graph Neural Networks for APT Attack Detection

Yazhou Du, Yu Chia Hong, Weiwu Ren · 2024

Advanced Persistent Threats are a sophisticated and persistent form of cyberattack that pose significant threats to the information security of enterprises and governments. Traditional APT detection methods struggle to capture the long-term dependencies and complex patterns inherent in such attacks. To address this challenge, this study proposes a novel APT detection model, KGNN, which integrates KAN with GNN. The KGNN model leverages the strengths of both KAN and GNN by extracting entities and their relationships from APT threat intelligence to enhance the representation of graph features via the KAN network, and subsequently performs attack detection using GNN. Using a self-constructed dataset, experiments compared the performance of KGNN with traditional GNN-based methods. The results demonstrate that KGNN significantly outperforms traditional models in terms of accuracy, recall, and F1-score, showcasing its effectiveness and superiority in APT detection tasks.

Read the paper · More papers on PaperTik