Next Article in Journal
Research on Visual SLAM Algorithm Based on Improved LSD Line Feature Extraction Algorithm
Next Article in Special Issue
Differential and Linear Cryptanalysis of the IoT-Friendly MGFN Block Cipher
Previous Article in Journal
Machine Learning-Based Real-Time Detection and Mitigation of DoS Attacks in SDN-Based 5G Network
Previous Article in Special Issue
Rethinking Ransomware Protection Targets for AI Systems
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Hybrid Time–Position Embedding for Provenance-Based Intrusion Detection

1
Department of Electrical and Computer Engineering, Illinois Institute of Technology, Chicago, IL 60616, USA
2
Department of Computer Science, Lewis University, Romeoville, IL 60446, USA
*
Author to whom correspondence should be addressed.
Electronics 2026, 15(5), 1004; https://doi.org/10.3390/electronics15051004
Submission received: 3 November 2025 / Revised: 21 February 2026 / Accepted: 23 February 2026 / Published: 28 February 2026

Abstract

Provenance-based Intrusion Detection Systems (IDSs) model the causal relationships between security events through a provenance graph and learn contextual information to detect Advanced Persistent Threats (APTs) effectively. However, existing provenance graph representation methods fail to fully reflect the characteristics of security domain data and the semantic information embedded in system logs, resulting in limited learning efficiency and detection accuracy. This paper proposes a provenance representation method that effectively captures security context from system log data. The proposed method improves the performance of provenance-based IDSs by combining (1) a provenance graph construction technique that transforms meaningful string attributes—such as command lines, process names, and file paths—into vector representations to extract semantic information in the security context, (2) a hybrid time–position embedding technique for capturing causal relationships between events, and (3) an iterative refinement learning strategy tailored to the characteristics of system log data. Experimental results using the DARPA Transparent Computing Engagement 3 (E3) benchmark dataset for APT detection demonstrate that our method achieves improved accuracy compared to existing approaches while significantly accelerating convergence during iterative training. These results suggest that the proposed embedding technique can more effectively capture abnormal temporal patterns, such as the long dwell times characteristic of APT attacks.
Keywords: data provenance; intrusion detection; embedding; semantic information data provenance; intrusion detection; embedding; semantic information

Share and Cite

MDPI and ACS Style

Gong, S.; Cho, J.; Choi, K.K. Hybrid Time–Position Embedding for Provenance-Based Intrusion Detection. Electronics 2026, 15, 1004. https://doi.org/10.3390/electronics15051004

AMA Style

Gong S, Cho J, Choi KK. Hybrid Time–Position Embedding for Provenance-Based Intrusion Detection. Electronics. 2026; 15(5):1004. https://doi.org/10.3390/electronics15051004

Chicago/Turabian Style

Gong, Seonghyeon, Jake Cho, and Kyuwon Ken Choi. 2026. "Hybrid Time–Position Embedding for Provenance-Based Intrusion Detection" Electronics 15, no. 5: 1004. https://doi.org/10.3390/electronics15051004

APA Style

Gong, S., Cho, J., & Choi, K. K. (2026). Hybrid Time–Position Embedding for Provenance-Based Intrusion Detection. Electronics, 15(5), 1004. https://doi.org/10.3390/electronics15051004

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop