Chainbreaker: A Graph-Based Framework For Flow-Level Persistent Advanced Threat Detection, Attack Chain Reconstruction, And Forensic Investigation

Authors

  • M.R. Padmapriya
  • Dr. I. Bremnavas
  • Vijayakumar Adaikalam
  • Gopinath. P.G
  • Nanthini K
  • J Puspha

Keywords:

Advanced Persistent Threats, Attack Graph, Cyber Kill Chain, Graph-Based Intrusion Detection, MITRE ATT&CK, Neo4j, Network Intrusion Detection System, XGBoost, Isolation Forest, CICIoT2023, Apache Spark, Temporal Aggregation, Forensic Analysis, Kill Chain Interruption.

Abstract

Advanced Persistent Threat (APT) detection remains difficult due to the multi-phase nature of these attacks and the inability to accurately infer them from individual network flows. Current flow-based classification methods can classify traffic individually, but cannot track the context of the attack. To solve this problem, the paper introduces a graph-based APT detection and forensics system called ChainBreaker. Network flow analysis is done using XGBoost model for attacks, and Isolation Forest for anomalies. Detection is assigned to one of the nine MITRE ATT&CK kill chain phases, and then each phase is incrementally represented as live Neo4j property graph that allows incremental building of attack progression by interconnected AttackEvent and KillChainStage objects. Meanwhile, the Apache Spark temporal analytics layer detects coordinated activities such as password spraying and distributed flooding that are not visible in individual flow analysis. In contrast to traditional security architectures that use separate log stores and correlation engines, the proposed architecture maintains a unified graph representation to detect, correlate, and investigate attacks and incidents through graph traversal. The effectiveness of this model was measured using the CICIoT2023 dataset, which consisted of 34 attack types and over 5.3 million network flows. The results showed that validation accuracy of 99.59% and an ROC-AUC score of 0.9999 were achieved using the XGBoost algorithm, but this approach allowed for a complete graph-based construction of the attacks.

Downloads

Published

2026-06-14

How to Cite

Padmapriya, M., Bremnavas, D. I., Adaikalam, V., P.G, G., K, N., & Puspha, J. (2026). Chainbreaker: A Graph-Based Framework For Flow-Level Persistent Advanced Threat Detection, Attack Chain Reconstruction, And Forensic Investigation. International Journal of Artificial Intelligence and Machine Learning, 6(5s), 497–513. Retrieved from https://svedbergopen.com/index.php/ijaiml/article/view/603