Causal graph–based root-cause attribution for multi-stage enterprise attacks

Main Article Content

Imran Gurbanaliyev

Abstract

Multi-stage enterprise cyberattacks generate complex and fragmented security telemetry across endpoints, identity systems, networks, and cloud platforms. Although modern security tools can detect suspicious activities, determining the underlying root cause of an incident remains a major challenge for effective and timely response. This paper presents a causal graph–based approach for root-cause attribution in multi-stage enterprise attacks. Security entities and events are represented as typed nodes within a directed causal graph that captures plausible cause–effect relationships. Root-cause hypotheses are ranked by evaluating feasible causal paths under temporal constraints and telemetry uncertainty. The proposed approach produces interpretable causal narratives that link observed evidence to initiating attack factors, supporting more accurate and targeted incident response decisions. By reducing investigation time and improving explanation reliability, the method strengthens enterprise cyber resilience and supports the continuity of digital infrastructures.


Google Scholar


Article Details

How to Cite
Gurbanaliyev, I. (2026). Causal graph–based root-cause attribution for multi-stage enterprise attacks. Scientific Collection «InterConf», (281), 162–167. Retrieved from https://archive.interconf.center/index.php/conference-proceeding/article/view/7834

References

Cheng, B., Yang, Z., & Li, M. (2025). Using causality-driven graph representation learning for APT attacks path identification. Symmetry, 17(9), 1373. https://doi.org/10.3390/sym17091373

Cui, M., Jiang, Z., Li, S., Ma, C., Zhang, K., Yang, P., & Feng, H. (2025). MGDA: A provenance graph-based framework for threat detection and attack scenario reconstruction. Computer Networks, 274, 111806. https://doi.org/10.1016/j.comnet.2025.111806

European Union Agency for Cybersecurity (ENISA). (2023). ENISA Threat Landscape 2023. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023

Guo, R., Cheng, L., Li, J., Hahn, P. R., & Liu, H. (2020). A survey of learning causality with data: Problems and methods. ACM Computing Surveys, 53(4), Article 75. https://doi.org/10.1145/3397269

Konsta, A.-M., Lluch Lafuente, A., Spiga, B., & Dragoni, N. (2024). Survey: Automatic generation of attack trees and attack graphs. Computers & Security, 139, 103602. https://doi.org/10.1016/j.cose.2023.103602

Kuikka, V., Pykälä, L., Takko, T., & Kaski, K. K. (2025). Network modelling in analysing cyber-related graphs. Frontiers in Complex Systems. https://doi.org/10.3389/fcpxs.2025.1620260

Li, M., Li, Z., Yin, K., Nie, X., Zhang, W., Sui, K., & Pei, D. (2022). Causal inference-based root cause analysis for online service systems with intervention recognition. In Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD ’22), 3230–3240. https://doi.org/10.1145/3534678.3539041

Yusof, A., Li, S., Kawatra, A. S., Li, D., Chang, E.-C., & Liang, Z. (2025). From observations to insights: Constructing effective cyberattack provenance with PROVCON. In Workshop on SOC Operations and Construction (WOSOC), co-located with NDSS 2025. https://www.ndss-symposium.org/ndss-paper/auto-draft-549/