Related Experiment Videos
Advanced Persistent Threat detection through Sequential Analysis of Network patterns with Graph based Learning
Vishnu Priya M K1, Sivabalan S1, Anila Glory H1
1Centre for Information Super Highway (CISH), School of Computing, SASTRA Deemed University, Thanjavur, Tamil Nadu, India.
Scientific Reports
|April 29, 2026
Summary
Advanced Persistent Threat (APT) attacks in Industrial Internet of Things (IIoT) are challenging. A new Sequential Analysis of Network patterns with Graph-based Learning (SANGL) approach enhances APT detection and cyber defense in IIoT environments.
Area of Science:
- Cybersecurity
- Network Security
- Machine Learning in IIoT
Background:
- Advanced Persistent Threats (APTs) pose significant risks to Industrial Internet of Things (IIoT) environments due to their complex, multi-stage attack patterns.
- Existing Machine Learning and Deep Learning models struggle to capture the evolving nature and intricate patterns of APTs.
- The disruption caused by APTs can severely damage operational systems and network environments.
Purpose of the Study:
- To propose a novel Sequential Analysis of Network patterns with Graph-based Learning (SANGL) approach for robust APT attack detection and mitigation in IIoT.
- To enhance the detection of evolving APT behaviors and accurately model stage-wise transitions in APT attacks.
- To improve the overall cyber defense mechanisms against sophisticated threats in IIoT.
Main Methods:
- The SANGL approach integrates PyPCA for critical APT pattern extraction.
- A motif hypergraph method clusters higher-order relationships between APT stages using motif augmentation and an attention mechanism.
- An Optimized Graph Convolution Network, modulated by MoGraM, is employed for enhanced detection of evolving APT behaviors.
Main Results:
- The SANGL approach demonstrated significant improvements in APT detection across multiple datasets (CICAPT IIoT, DAPT20, Unraveled, Edge IIoT).
- Performance was validated against state-of-the-art models using metrics like Accuracy, Precision, Detection Rate, and F1-score.
- The method showed enhanced accuracy in Attention Divergence Score, Stage Contrastiveness score, and Stage Transition accuracy.
Conclusions:
- The proposed SANGL approach offers a robust solution for detecting and mitigating APT attacks in IIoT environments.
- SANGL effectively captures the nuanced evolution and intricate patterns of APTs, outperforming existing methods.
- This advancement significantly enhances the cyber defense capabilities for IIoT systems against sophisticated threats.