Graph-Based Correlation Method for Information Security Incidents with Automatic Construction of Attack Chains

DOI: 10.21293/1818-0442-2025-28-3-89-96

Download article in PDF format

JATS xml

Abstract: This paper presents a method for automated correlation of information security incidents originating from various security tools (SIEM, EDR, NTA) based on graph models. The proposed approach considers the severity of incidents according to CVSS (Common Vulnerability Scoring System) metrics, the prioritization of MITRE ATT&CK techniques, and the temporal proximity of events. To filter out secondary entities, a TF-IDF algorithm is applied. The method implements graph-based incident correlation with automatic construction of attack chains while minimizing analyst involvement, thereby increasing accuracy and reducing the number of false-positive connections. The effectiveness of the method was validated through experiments in an isolated cyber laboratory: automated correlation reduced analysis time by 99,82% compared to manual processing. The results demonstrate the potential of using graph structures in cybersecurity systems.

Keywords: graph models, incident correlation, information security, SOC, SIEM, EDR, NTA, CVSS, MITRE ATT&CK, TF-IDF, automated analysis, incident analysis

For citation:
Dolgachev M. V., Kostyunin V. A. Graph-Based Correlation Method for Information Security Incidents with Automatic Construction of Attack Chains. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2025, vol. 28, no. 3, pp. 89–96. DOI: 10.21293/1818-0442-2025-28-3-89-96

Authors and copyright holders:

  • 1. Gurina A.O., Guzev O.Yu., Eliseev V.L. [Host anomalies detection using autoencoders]. International Journal of Open Information Technologies, 2020, vol. 8, no. 8, pp. 26–35 (in Russ.).
  • 2. Moskvichev A.D., Dolghachev M.V. Algoritmy korrelyatsii sobytii informatsionnoi bezopasnosti [Event correlation algorithms for information security]. Avtomatizatsiya processov upravleniya, 2020, no. 3, pp. 50–59 (in Russ.).
  • 3. Korolev I.D., Litvinov E.S., Pestov S.V. Analiz potokov dannyh o sobytiyah i intsidentah informatsionnoj bezopasnosti, postupayushchih iz raznorodnyh istochnikov [Analysis of data flows of events and information security incidents from heterogeneous sources]. Rezultaty sovremennyh nauchnyh issledovanii i razrabotok: Sbornik statei VIII Vserossijskoi nauchno-prakticheskoi konferetscii [Results of Modern Scientific Research and Development. Proceedings of the VIII AllRussian Scientific and Practical Conference]. Penza, Nauka i Prosveshchenie (G.Yu. Gulyaev, IE), 2020, pp. 26–34 (in Russ.).
  • 4. Belyaev P.A. [Methods for detecting anomalous and malicious user behavior, abnormal activity detection technologies]. Forum of Young Scientists, 2021, no. 6 (58), pp. 139–142 (in Russ.).
  • 5. Rybakov D.A. [Automated detection of cyberattacks in information technologies]. Vestnik Nauki, 2023, vol. 5, no. 7 (64), pp. 250–255 (in Russ.).
  • 6. Xu Liwen, Zhang X., Li Y. HiSec: Towards Cyber Threat Correlation and Discovery Based on Hierarchical Graph Neural Networks. IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Devon, United Kingdom, 2023, pp. 369–378.
  • 7. Yang F., Song J., Li H. ProGrapher: An Anomaly Detection System based on Provenance Graph Embedding. Proceedings of USENIX Security Symposium, Anaheim, CA, USA, USENIX Association, 2022, pp. 4355–4372.
  • 8. Bhattarai B., Huang H. Prov2vec: Learning Provenance Graph Representation for Anomaly Detection in Computer Systems. International Conference on Availability, Reliability and Security (ARES), Vienna Austria, Association for Computing Machinery, 2024. pp. 135–144.
  • 9. Pelofske E. et al. Cybersecurity Threat Hunting and Vulnerability Analysis Using a Neo4j Graph Database of Open Source Intelligence. arXiv preprint arXiv:2301.12013, 2023. Available at: https://arxiv.org/abs/2301.12013 (Accessed: 22 February 2025).
  • 10. Xu J., Wu Y., Chen D. Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security Analytics. IEEE Symposium on Security and Privacy (SP), San Francisco, USA, IEEE, 2024, pp. 3590–3608.
  • 11. Aksu D., Tolmachov D., Nikolov A., Muslukhov I. Graph-based Detection of Cybersecurity Threats Using Markov Chains and Semi-supervised Learning. 2023 IEEE International Conference on Big Data (Big Data), Sorrento, Italy, 2023, pp. 398–406.
  • 12. Rahman M.R., Williams L. Investigating co-occurrences of MITRE ATT&CK Techniques. arXiv preprint arXiv:2211.06495, 2022. Available at: https://arxiv.org/pdf/2211.06495 (Accessed: 21 February 2025).
  • 13. Detection Engineering Backlog Prioritization. Kaspersky Lab, 2023. Available at: https://securelist.ru/detection-engineering-backlog-prioritization/109883/ (Accessed: 25 February 2025).
  • 14. Artamonov N.V., Ivin E.A., Kurbatsky A.N., Fantazzini D. Vvedenie v analiz vremennyh ryadov: uchebnoye posobie dlya vuzov [Introduction to Time Series Analysis: Textbook for Universities]. Moscow State University named after M.V. Lomonosov, Moscow School of Economics, 2021, pp. 134 (in Russ.).
  • 15. Khoroshilov A.A., Kan A.V., Evdokimova E.A., Pitskhelauri S.G. [Establishing similarity between text documents]. Modeling and Data Analysis, 2023, vol. 13, no. 4, pp. 45–58 (in Russ.).
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates