Anomaly detection with graph transformer networks in windows event logs
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
This research presents a graph-based approach inspired by Graph Transformer Network (GTN) to analyze data from Windows Event Logs to increase the effectiveness of the security system against increasing cyber threats. The GCN-based structure on which GTN is based opens new possibilities for analyzing complex and diverse data sources by focusing on detailed examination of Windows event logs. The event logs in the dataset used include registry and system changes, security breaches, and threat simulations. The dataset consists of event log data simulating the tactics, techniques, and procedures of advanced threat actors. This approach helps strengthen existing security solutions and develop new defense strategies. At the same time, research results using this dataset can provide cybersecurity experts and researchers with a better understanding of attack vectors and attack surfaces. This study models each event in the dataset and the interactions between events in a graph-based structure. In GTN-based models, each event is represented as a node, and the edges between nodes show the interactions and connections of these events, thus revealing the relational connections and structural patterns within complex cyber threat scenarios. By learning complex structural patterns and connections in these graphs, GTN can distinguish between normal and abnormal behaviors. This approach is effective in identifying subtle details and relationships that traditional security systems may miss. Unlike conventional graph-based neural networks, the GTN model is better at learning long-distance connections and large structural patterns, which is important for processing complex data such as Windows Event Logs. This study will demonstrate the application of an approach inspired by GTN principles on a detailed dataset, facilitating a better understanding and identification of cybersecurity threats, ultimately improving threat detection and analysis methods in the cybersecurity field, and significantly contributing to the existing literature on cybersecurity.
Author
Tuba Şengün Bakıcı
How to Cite
Tuba Şengün Bakıcı (Master Thesis). Anomaly detection with graph transformer networks in windows event logs, 2025, Fırat University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Fırat University
- Using social media as an integrated marketing communication tool(2018)
- Foundation of Dutch East İndia Company and her rising in İndonesia in the 17th century(2013)
- Examination of stress state between Doğanyol (Malatya) and Çelikhan (Adıyaman) on the east Anatolian fault zone(2020)
- Color usage at Turkish Divan of Fuzûlî(2013)
- Yavuzeli (Gaziantep) surrounding volcanic outcropping of rocks petrographic and geochemical features(2014)
- Hizbu?t-Tahrir and the religions and political thoughts of Ercumend Özkan(2008)