Causal graph–based root-cause attribution for multi-stage enterprise attacks
Main Article Content
Abstract
Multi-stage enterprise cyberattacks generate complex and fragmented security telemetry across endpoints, identity systems, networks, and cloud platforms. Although modern security tools can detect suspicious activities, determining the underlying root cause of an incident remains a major challenge for effective and timely response. This paper presents a causal graph–based approach for root-cause attribution in multi-stage enterprise attacks. Security entities and events are represented as typed nodes within a directed causal graph that captures plausible cause–effect relationships. Root-cause hypotheses are ranked by evaluating feasible causal paths under temporal constraints and telemetry uncertainty. The proposed approach produces interpretable causal narratives that link observed evidence to initiating attack factors, supporting more accurate and targeted incident response decisions. By reducing investigation time and improving explanation reliability, the method strengthens enterprise cyber resilience and supports the continuity of digital infrastructures.
Article Details
References
Cheng, B., Yang, Z., & Li, M. (2025). Using causality-driven graph representation learning for APT attacks path identification. Symmetry, 17(9), 1373. https://doi.org/10.3390/sym17091373
Cui, M., Jiang, Z., Li, S., Ma, C., Zhang, K., Yang, P., & Feng, H. (2025). MGDA: A provenance graph-based framework for threat detection and attack scenario reconstruction. Computer Networks, 274, 111806. https://doi.org/10.1016/j.comnet.2025.111806
European Union Agency for Cybersecurity (ENISA). (2023). ENISA Threat Landscape 2023. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023
Guo, R., Cheng, L., Li, J., Hahn, P. R., & Liu, H. (2020). A survey of learning causality with data: Problems and methods. ACM Computing Surveys, 53(4), Article 75. https://doi.org/10.1145/3397269
Konsta, A.-M., Lluch Lafuente, A., Spiga, B., & Dragoni, N. (2024). Survey: Automatic generation of attack trees and attack graphs. Computers & Security, 139, 103602. https://doi.org/10.1016/j.cose.2023.103602
Kuikka, V., Pykälä, L., Takko, T., & Kaski, K. K. (2025). Network modelling in analysing cyber-related graphs. Frontiers in Complex Systems. https://doi.org/10.3389/fcpxs.2025.1620260
Li, M., Li, Z., Yin, K., Nie, X., Zhang, W., Sui, K., & Pei, D. (2022). Causal inference-based root cause analysis for online service systems with intervention recognition. In Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD ’22), 3230–3240. https://doi.org/10.1145/3534678.3539041
Yusof, A., Li, S., Kawatra, A. S., Li, D., Chang, E.-C., & Liang, Z. (2025). From observations to insights: Constructing effective cyberattack provenance with PROVCON. In Workshop on SOC Operations and Construction (WOSOC), co-located with NDSS 2025. https://www.ndss-symposium.org/ndss-paper/auto-draft-549/
