Graph Neural Network-Based Detection of Lateral Movement and Compromised Identity Paths in Multi-Cloud Environments
Keywords:
zero trust, temporal graph, provenance graph, attack path, multi-cloud security, GNNAbstract
Background: Multi-cloud adoption fragments identity, authorization, workload, network, and audit evidence across providers. Lateral movement therefore appears less as a single anomalous event than as a sequence of weakly suspicious identity-to-resource transitions. Graph neural networks (GNNs) are structurally suited to this problem, but the evidence has not been synthesized around compromised identity paths.
Objective: To assess how graph-based learning has been used to detect lateral movement, compromised hosts or identities, advanced persistent threats, and multi-stage intrusion paths; to determine readiness for multi-cloud deployment; and to derive an identity-path-centered reference architecture and evaluation agenda.
Methods: A systematic mapping review searched major engineering and publisher indexes for English-language empirical journal studies published from January 2018 through 2 September 2026. Eligible studies applied a GNN or neural graph-representation method to network, host, cloud, lateral-movement, or attack-path detection and reported an empirical evaluation. Twenty-two DOI-verified studies met the criteria. Data were coded for graph semantics, temporal modeling, learning regime, output granularity, datasets, performance, explainability, robustness, privacy, and deployment realism. Owing to heterogeneous tasks and datasets, findings were synthesized narratively and by capability counts rather than meta-analysis.
Results: Traffic or communication graphs dominated the evidence (15/22), while six studies used provenance, alert, or cyber-threat-intelligence graphs. Explicit temporal modeling appeared in eight studies, and seven produced a path, trace, route, or forecast output. Only one study explicitly modeled authentication-centered lateral movement, one evaluated a dedicated adversarial defense, and one used federated learning. No included study validated a unified identity-to-resource graph across multiple cloud providers, and none reported calibrated uncertainty for path-level decisions. Reported classification performance was often high, but benchmark reuse, non-comparable graph definitions, limited temporal holdout, and sparse operational validation constrained generalizability.
Conclusion: The literature supports heterogeneous, temporal, self-supervised GNNs as a promising foundation for multi-cloud lateral-movement detection, but current systems remain telemetry-siloed and classification-centric. Progress requires canonical cross-provider identity semantics, token and privilege lineage, multi-task path scoring, calibrated uncertainty, causal explanations, privacy-preserving collaboration, and evaluation on temporally ordered multi-cloud attack campaigns.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Viral Dhirenkumar Pala (Author)

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors retain copyright in their published work.
Articles published by the International Journal of Business & Computational Sciences (IJBCS) are distributed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License (CC BY-NC-ND 4.0).
Under this license, users may copy and redistribute the published material in any medium or format for non-commercial purposes, provided that appropriate credit is given to the author(s) and the International Journal of Business & Computational Sciences, a link to the license is provided, and the material is not modified, adapted, remixed, transformed, or built upon.
The full terms of the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License are available at: