Graph-Based Correlation Method for Information Security Incidents with Automatic Construction of Attack Chains
DOI: 10.21293/1818-0442-2025-28-3-89-96
DOI: 10.21293/1818-0442-2025-28-3-89-96
Abstract: This paper presents a method for automated correlation of information security incidents originating from various security tools (SIEM, EDR, NTA) based on graph models. The proposed approach considers the severity of incidents according to CVSS (Common Vulnerability Scoring System) metrics, the prioritization of MITRE ATT&CK techniques, and the temporal proximity of events. To filter out secondary entities, a TF-IDF algorithm is applied. The method implements graph-based incident correlation with automatic construction of attack chains while minimizing analyst involvement, thereby increasing accuracy and reducing the number of false-positive connections. The effectiveness of the method was validated through experiments in an isolated cyber laboratory: automated correlation reduced analysis time by 99,82% compared to manual processing. The results demonstrate the potential of using graph structures in cybersecurity systems.
Keywords: incident analysis, auto-mated analysis, tf-idf, mitre att&ck, cvss, nta, edr, siem, soc, information security, incident correlation, graph models
Authors and copyright holders:
—
For citation:
Dolgachev M. V., Kostyunin V. A. Graph-Based Correlation Method for Information Security Incidents with Automatic Construction of Attack Chains. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2025, vol. 28, no. 3, pp. 89–96. DOI: 10.21293/1818-0442-2025-28-3-89-96
Executive Secretary of the Editor’s Office
Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia
Phone / Fax: + 7 (3822) 701-582
Viktor N. Maslennikov
Executive Secretary of the Editor’s Office
Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia
Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02