Research on the emergency response method of Windows system based on malicious attack behavior

KunSan Zhang, Chen Chen, Lin Xiao-ping, JinHuang Lin, Siqi Pan, Zheng Huang · 2025

Focusing on the escalating security threats posed by Advanced Persistent Threats (APT) and ransomware targeting Windows systems, this paper presents an innovative dynamic emergency response framework that integrates advanced behavioral pattern recognition technologies with automated mitigation capabilities. By constructing a multidimensional attack feature system, the framework incorporates a novel causal inference algorithm based on Graph Neural Networks (GNN), enabling precise attack chain reconstruction and real-time threat analysis. Additionally, the framework implements kernel-level traffic control and memory forensics technologies to ensure comprehensive system protection. Experimental results demonstrate the framework's exceptional performance: it reduces the average response time for ransomware attacks to 2.3 minutes (an 83% improvement over traditional methods), achieves a lateral movement detection accuracy of 95.2%, and maintains a false positive rate below 1.8%. These findings not only validate the framework's effectiveness but also provide a robust theoretical foundation and practical implementation pathway for building adaptive security protection systems capable of addressing evolving cyber threats.

Read the paper · More papers on PaperTik