Every Month Last Day ISSN (online): 1934-9955

International Journal Of Imaging

Science And Engineering

We welcome original or extended version of previously published papers in conferences and/or journals. Every Month Last Day Volume 11, Issue 127, August edition has been published. Authors are requested to take a look. MÃ¥nedlig webinar: 15 September 2024 - 18:00 GMT +1
Abstract

Post-Compromise Behavior Analysis in Enterprise Networks Using Graph Anomaly Detection

Author: Lohith Vanama

Abstract:

After initial compromise, adversaries often rely on stealthy lateral movement and privilege escalation to complete their objectives. Detecting such activity requires correlating diverse events across users, systems, and time. This paper introduces a graph-based anomaly detection approach for identifying post-compromise behaviors in enterprise networks. Using authentication logs, Active Directory data, VPN access logs, and process trees, we build dynamic user-resource interaction graphs. These are processed using GraphSAGE and subgraph matching algorithms to identify deviations from normal communication paths and resource usage patterns. The system is evaluated on real-world datasets from two enterprise SOCs and enriched with simulated attack paths involving techniques from the MITRE ATT&CK framework. Our model achieves a precision of 89% and recall of 84% in identifying suspicious privilege escalation chains and unusual remote desktop access paths. Time-aware embeddings impr

Download PDF
Contents are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Privacy Policy | Terms of Use