{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/euler-detecting-network-lateral-movement-via","title":"Euler: Detecting Network Lateral Movement via Scalable Temporal Link Prediction","arxiv_id":null,"date":"2022-04-24","proceeding":"NDSS 2022 4","authors":["Isaiah J. King","H. Howie Huang"],"abstract":"Lateral movement is a key stage of system compromise used by advanced persistent threats. Detecting it is no\r\nsimple task. When network host logs are abstracted into discrete temporal graphs, the problem can be reframed as anomalous edge detection in an evolving network. Research in modern deep graph learning techniques has produced many creative and complicated\r\nmodels for this task. However, as is the case in many machine learning fields, the generality of models is of paramount importance for accuracy and scalability during training and inference. In this paper, we propose a formalized approach to this problem with a framework we call EULER. It consists of a model-agnostic graph neural network stacked upon a model-agnostic sequence encoding layer such as a recurrent neural network. Models built according to the EULER framework can easily distribute their graph convolutional layers across multiple machines for large performance improvements. Additionally, we demonstrate that EULER-based models are competitive, or better than many state-of-the-art approaches to anomalous link detection and prediction. As anomaly-based intrusion detection systems, EULER models can efficiently identify anomalous connections between entities with high precision and outperform \r\n other unsupervised techniques for anomalous lateral movement detection.","url_abs":"https://www.ndss-symposium.org/ndss-paper/auto-draft-227/","url_pdf":"https://www.ndss-symposium.org/wp-content/uploads/2022-107A-paper.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"euler-detecting-network-lateral-movement-via","repo_url":"https://github.com/iHeartGraph/Euler","is_official":0,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"dynamic-link-prediction","task_name":"Dynamic Link Prediction"},{"task_slug":"edge-detection","task_name":"Edge Detection"},{"task_slug":"graph-learning","task_name":"Graph Learning"},{"task_slug":"graph-neural-network","task_name":"Graph Neural Network"},{"task_slug":"intrusion-detection","task_name":"Intrusion Detection"},{"task_slug":"link-prediction","task_name":"Link Prediction"}],"methods":[{"method_slug":"graph-neural-network","method_name":"Graph Neural Network"}],"datasets_introduced":[],"methods_introduced":[],"results":[{"leaderboard":"/sota/dynamic-link-prediction-on-dblp-temporal","task":"Dynamic Link Prediction","dataset":"DBLP Temporal","model":"Euler","rank_in_archive_order":2,"of":7,"metrics":{"AP":"89.03","AUC":"86.54"},"uses_additional_data":false},{"leaderboard":"/sota/dynamic-link-prediction-on-enron-email","task":"Dynamic Link Prediction","dataset":"Enron Emails","model":"Euler","rank_in_archive_order":1,"of":7,"metrics":{"AP":"94.10","AUC":"93.15"},"uses_additional_data":false}],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}