Distributed Temporal Graph Learning with Provenance for APT Detection in Supply Chains

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tan, Zhuoran, Anagnostopoulos, Christos, Singer, Jeremy
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909563346747392
author Tan, Zhuoran
Anagnostopoulos, Christos
Singer, Jeremy
author_facet Tan, Zhuoran
Anagnostopoulos, Christos
Singer, Jeremy
contents Cyber supply chain, encompassing digital asserts, software, hardware, has become an essential component of modern Information and Communications Technology (ICT) provisioning. However, the growing inter-dependencies have introduced numerous attack vectors, making supply chains a prime target for exploitation. In particular, advanced persistent threats (APTs) frequently leverage supply chain vulnerabilities (SCVs) as entry points, benefiting from their inherent stealth. Current defense strategies primarly focus on prevention through blockchain for integrity assurance or detection using plain-text source code analysis in open-source software (OSS). However, these approaches overlook scenarios where source code is unavailable and fail to address detection and defense during runtime. To bridge this gap, we propose a novel approach that integrates multi-source data, constructs a comprehensive dynamic provenance graph, and detects APT behavior in real time using temporal graph learning. Given the lack of tailored datasets in both industry and academia, we also aim to simulate a custom dataset by replaying real-world supply chain exploits with multi-source monitoring.
format Preprint
id arxiv_https___arxiv_org_abs_2504_02313
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Distributed Temporal Graph Learning with Provenance for APT Detection in Supply Chains
Tan, Zhuoran
Anagnostopoulos, Christos
Singer, Jeremy
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Cyber supply chain, encompassing digital asserts, software, hardware, has become an essential component of modern Information and Communications Technology (ICT) provisioning. However, the growing inter-dependencies have introduced numerous attack vectors, making supply chains a prime target for exploitation. In particular, advanced persistent threats (APTs) frequently leverage supply chain vulnerabilities (SCVs) as entry points, benefiting from their inherent stealth. Current defense strategies primarly focus on prevention through blockchain for integrity assurance or detection using plain-text source code analysis in open-source software (OSS). However, these approaches overlook scenarios where source code is unavailable and fail to address detection and defense during runtime. To bridge this gap, we propose a novel approach that integrates multi-source data, constructs a comprehensive dynamic provenance graph, and detects APT behavior in real time using temporal graph learning. Given the lack of tailored datasets in both industry and academia, we also aim to simulate a custom dataset by replaying real-world supply chain exploits with multi-source monitoring.
title Distributed Temporal Graph Learning with Provenance for APT Detection in Supply Chains
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2504.02313