A Graph Neural Diffusion Network for Sophisticated Persistent Threat Hunting in IoT Environments
Mounica Yenugula, Bhargavi Konda, Vinay Kumar Kasula, Akhila Reddy Yadulla, Chaitanya Tumma, Sarath Babu Rakki · 2025
Sophisticated Persistent Threats (SPTs) in IoT environments exhibit strong concealment, extended durations, and rapid evolution, making traditional passive detection methods inadequate for effective threat identification. To address these challenges, this paper proposes a Threat Hunting model based on a Graph Neural Diffusion Network (GNDN), which excels in capturing multi-scale relationships and dynamic features within IoT systems. The model transforms input Cyber Threat Intelligence (CTI) log graphs and IoT kernel audit log graphs into enriched graph representations. A GNDN layer is employed to diffuse critical information across graph nodes, capturing both local and global dependencies. Furthermore, a pre-trained Transformer encoder fine-tuned for temporal and positional encoding processes these enriched graphs to enhance feature representation. Finally, similarity scores are calculated through attention-based graph matching to identify SPT traces. Experiments conducted in a simulated IoT environment demonstrate that the proposed GNDN model reduces mean squared error by approximately 22%, increases Spearman rank correlation by 1.3%, and improves matching accuracy by around 2.0% compared to state-of-the-art graph neural networks.