← all papers · overview

Semantic and Graph-based Adaptive Threat Detection for Industrial Internet of Things Logs

Abstract

The Industrial Internet of Things (IIoT) technology is emerging, resulting in rapid changes and more visibility of machine-generated data, improved situational awareness and increased control of industrial maintenance. However, heterogeneous log formats create serious cyber threat vulnerability and complicated security issues. This paper presents a framework for Semantic and Graph-Based Adaptive Threat Detection as a means of dealing with these difficulties in IIoT systems. The framework has two parts; first, a hybrid log analyzer utilizes both rules-based analysis and low-complexity language models to extract key entities and relationships from diverse logs following an ontology for IIoT. The outputs of these analyses create heterogeneous graphs that reflect both contextual and temporal dependencies through the numerical representation of the nodes' and edges' embeddings. Second, by using an improved Temporal Graph Network (TGN) based upon adaptive relationship models, the TGN learns dynamic relationships between the nodes, thus detecting deviations in behaviour through the application of Extreme Value Theory (EVT) to automatically adjust the threshold for anomaly detection. By aggregating a pattern of suspicious activity found in the heterogeneous graphs through community detection, the coherent attack paths can then be related back to the interpretation of threat-based techniques described in the MITRE ATT&CK database. The experimental results show an increase in detection precision, decreased false positive results and improved real-time adaptation when compared to previous efforts. The proposed framework provides an intelligent, context-aware, scalable and explainable solution for IIoT systems.

Related papers

Ranked by semantic similarity — how closely each paper's abstract matches this one (100% = near-identical topic).