中文

面向供应链中 APT 检测的分布式时序图学习及其来源追踪

密码学与安全 2025-04-04 v1 分布式、并行与集群计算

摘要

网络供应链涵盖数字资产、软件、硬件,已成为现代信息和通信技术(ICT) provisioning 的 essential 组件。然而,日益增长的相互依赖性引入了诸多攻击向量,使供应链成为受欢迎的 exploitation 目标。特别是,高级持续性威胁(APT)经常利用供应链漏洞(SCV)作为入口点,受益于其天然的 stealth 特性。当前的防御策略主要通过区块链实现完整性保证的 prevention,或利用开源软件(OSS)中的 plain-text source code analysis 实现 detection。然而,这些方法忽略了 source code 不可得的情况,未能解决 runtime 期间的 detection 与 defense。为弥合这一差距,我们提出了一种新方法,集成多源数据,构建全面的 dynamic provenance graph,并通过时序图学习实现实时 APT 行为 detection。鉴于行业和学术界缺乏量身定制的数据集,我们也致力于通过 replay 真实世界的 supply chain exploits 来模拟自定义数据集,并进行多源监控。

关键词

引用

@article{arxiv.2504.02313,
  title  = {Distributed Temporal Graph Learning with Provenance for APT Detection in Supply Chains},
  author = {Zhuoran Tan and Christos Anagnostopoulos and Jeremy Singer},
  journal= {arXiv preprint arXiv:2504.02313},
  year   = {2025}
}

备注

This paper has been accepted at 45th IEEE International Conference on Distributed Computing Systems