Radam, Fajra Hanifa Nuridi (2026) Deteksi Malware pada Sysmon Event Logs Berbasis Deteksi Anomali Graf dengan Korelasi Kejadian. Masters thesis, Institut Teknologi Sepuluh Nopember.
|
Text
6025241025-Master_Thesis.pdf - Accepted Version Restricted to Repository staff only Download (4MB) | Request a copy |
Abstract
Malware menjadi salah satu ancaman paling serius dalam keamanan siber yang menyebabkan kebocoran data, kerugian finansial, dan gangguan pada sistem-sistem penting. Penelitian ini mengusulkan metode deteksi malware dengan mengonversi Sysmon event logs yang terkorelasi menjadi bentuk graf, lalu menerapkan dua pendekatan berbasis Graph Neural Network (GNN), yaitu Graph Anomaly Detection (GAD) yang bersifat unsupervised dan klasifikasi node berbasis supervised learning. Event log dikorelasikan melalui relasi parent-child menggunakan struktur pohon, kemudian dimodelkan sebagai graf di mana node mewakili event dan edge mewakili hubungan antarproses. Lima metode GAD diimplementasikan, yaitu DOMINANT, OCGNN, CONAD, GAE, dan AnomalyDAE, sementara tiga metode supervised diimplementasikan sebagai pembanding, yaitu Graph Convolutional Network (GCN), Graph Attention Network (GAT), dan GraphSAGE. Evaluasi dilakukan menggunakan Precision, Recall, dan F1 Score pada skenario baseline dan hyperparameter tuning. Hasil terbaik pada GAD diperoleh CONAD dengan F1 Score sebesar 0,6368, sementara hasil terbaik pada supervised learning diperoleh GraphSAGE dengan F1 Score sebesar 0,9338. Perbandingan dengan penelitian sebelumnya yang menggunakan dataset serupa tanpa korelasi parent-child menunjukkan bahwa GAD belum mengungguli sebagian besar model machine learning konvensional pada penelitian tersebut, sementara GraphSAGE berhasil melampaui seluruh model supervised dan sebagian model unsupervised pada penelitian sebelumnya. Temuan ini mengindikasikan bahwa korelasi parent-child memberikan manfaat nyata terhadap deteksi malware ketika dipadukan dengan label selama pelatihan, sekaligus mengukur kesenjangan performa antara pendekatan unsupervised dan supervised pada konteks Sysmon event logs.
======================================================================================================================================
Malware is one of the most serious threats in cybersecurity, causing data breaches, financial losses, and disruption to critical systems. This study proposes a malware detection method by converting correlated Sysmon event logs into a graph structure, then applying two Graph Neural Network (GNN)-based approaches: Graph Anomaly Detection (GAD), which operates in an unsupervised manner, and node classification based on supervised learning. Event logs are correlated through parent-child relationships using a tree structure, then modeled as a graph where nodes represent events and edges represent inter-process relationships. Five GAD methods are implemented which are DOMINANT, OCGNN, CONAD, GAE, and AnomalyDAE, while three supervised methods are implemented as comparisons which are Graph Convolutional Network (GCN), Graph Attention Network (GAT), and GraphSAGE. Evaluation is conducted using Precision, Recall, and F1 Score across baseline and hyperparameter tuning scenarios. The best result for GAD is achieved by CONAD with an F1 Score of 0,6368, while the best result for supervised learning is achieved by GraphSAGE with an F1 Score of 0,9338. Comparison with the previous study which used a similar dataset without parent-child correlation, shows that GAD has not yet outperformed most conventional machine learning models in that study, while GraphSAGE successfully surpasses all supervised models and some unsupervised models in previous study. These findings indicate that parent-child correlation provides tangible benefits for malware detection when combined with labels during training, while also quantifying the performance gap between unsupervised and supervised approaches in the context of Sysmon event logs.
| Item Type: | Thesis (Masters) |
|---|---|
| Uncontrolled Keywords: | graf, graph anomaly detection, graph neural network, malware, sysmon event logs, graph, graph anomaly detection, graph neural network, malware, sysmon event logs |
| Subjects: | Q Science > QA Mathematics > QA76.87 Neural networks (Computer Science) Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science) Q Science > QA Mathematics > QA76.9.D343 Data mining. Querying (Computer science) |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55101-(S2) Master Thesis |
| Depositing User: | Fajra Hanifa Nuridi Radam |
| Date Deposited: | 30 Jul 2026 00:59 |
| Last Modified: | 30 Jul 2026 00:59 |
| URI: | http://repository.its.ac.id/id/eprint/139910 |
Actions (login required)
![]() |
View Item |
