Spatial-Temporal Graph Neural Network for the Detection of Container Escape Events

Spatial-Temporal Graph Neural Network for the Detection of Container Escape Events
复制标题

DOI:
10.5220/0012347800003636
复制
发表时间:
2024
期刊:
--
影响因子:
--
通讯作者:
Yu Guo;James Pope
Yu Guo;James Pope
中科院分区:
其他
文献类型:
--
作者:
Yu Guo;James Pope

文献摘要

相似文献

物联网(IoT)设备使攻击面更接近个人生活和工业生产。通过将容器作为物联网应用部署的主要方法,通过分析审计日志来检测容器逃逸可以识别受损的边缘设备。由于审计日志数据包含事件的时态属性和系统实体之间的关系信息,现有的分析方法不能全面分析这两个属性。本文设计了一种新的基于时序图神经网络(GNN)的模型来检测容器环境中物联网应用的异常。该模型采用门控递归单元(GRU)和图同构网络(GIN)算子来捕获时间和空间特征。使用无监督学习对应用程序的正常行为进行建模,该模型可以检测到在训练中未出现的未知异常。该模型是在审计日志生成的动态图上训练的,该图记录系统中的安全事件。由于缺乏真实世界的数据集,我们在模拟数据集上进行了实验。根据审计日志记录的时态属性将其划分为多个图,形成动态图。一些节点和边被聚合或移除以降低图的复杂性。在实验中,该模型在验证集上的F1得分为0.976,优于性能最好的基线模型,F1得分为0.845。
: Internet of Things (IoT) devices bring an attack surface closer to personal life and industrial production. With containers as the primary method of IoT application deployment, detecting container escapes by analyzing audit logs can identify compromised edge devices. Since audit log data contains temporal property of events and relational information between system entities, existing analysis methods cannot comprehensively analyze these two properties. In this paper, a new Temporal Graph Neural Network (GNN) -based model was designed to detect anomalies of IoT applications in a container environment. The model employed Gated Recurrent Unit (GRU) and Graph Isomorphism Network (GIN) operators to capture temporal and spatial features. Using unsupervised learning to model the application’s normal behavior, the model can detect unknown anomalies that have not appeared in training. The model is trained on a dynamic graph generated from audit logs, which records security events in a system. Due to the lack of real-world datasets, we conducted experiments on a simulated dataset. Audit log records are divided into multiple graphs according to their temporal attribute to form a dynamic graph. Some nodes and edges are aggregated or removed to reduce the complexity of the graph. In the Experiments, The model has an F1 score of 0.976 on the validation set, which outperforms the best-performing baseline model, with an F1 score of 0.845.