A baseline for unsupervised advanced persistent threat detection in system-level provenance

被引:13
|
作者
Berrada, Ghita [1 ]
Cheney, James [1 ,3 ]
Benabderrahmane, Sidahmed [1 ]
Maxwell, William [2 ]
Mookherjee, Himan [1 ]
Theriault, Alec [2 ]
Wright, Ryan [2 ]
机构
[1] Univ Edinburgh, Sch Informat, 10 Crichton St, Edinburgh, Midlothian, Scotland
[2] Galois Inc, Portland, OR USA
[3] Alan Turing Inst, London, England
基金
欧洲研究理事会;
关键词
Anomaly detection; Advanced persistent threats; Unsupervised learning; Cyber security; Provenance; DETECTION STRATEGY;
D O I
10.1016/j.future.2020.02.015
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Advanced persistent threats (APTs) are stealthy, sophisticated, and unpredictable cyberattacks that can steal intellectual property, damage critical infrastructure, or cause millions of dollars in damage. Detecting APTs by monitoring system-level activity is difficult because manually inspecting the high volume of normal system activity is overwhelming for security analysts. We evaluate the effectiveness of unsupervised batch and streaming anomaly detection algorithms over multiple gigabytes of provenance traces recorded on four different operating systems to determine whether they can detect realistic APT-like attacks reliably and efficiently. This article is the first detailed study of the effectiveness of generic unsupervised anomaly detection techniques in this setting. (C) 2020 Elsevier B.V. All rights reserved.
引用
收藏
页码:401 / 413
页数:13
相关论文
共 50 条
  • [21] Advanced Persistent Threat Detection: A Particle Swarm Optimization Approach
    Al Mamun, Abdullah
    Al-Sahaf, Harith
    Welch, Ian
    Camtepe, Seyit
    2022 32ND INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2022, : 42 - 49
  • [22] Detection: Definition of New Model to Reveal Advanced Persistent Threat
    Maccari, M.
    Polzonetti, A.
    Sagratella, M.
    PROCEEDINGS OF THE FUTURE TECHNOLOGIES CONFERENCE (FTC) 2018, VOL 2, 2019, 881 : 305 - 323
  • [23] A Comprehensive Survey on Advanced Persistent Threat (APT) Detection Techniques
    Krishnapriya, Singamaneni
    Singh, Sukhvinder
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 80 (02): : 2675 - 2719
  • [24] Advanced Persistent Threat Attack Detection using Clustering Algorithms
    Alsanad, Ahmed
    Altuwaijri, Sara
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (09) : 640 - 649
  • [25] Advanced Persistent Threat Detection Method Research Based on Relevant Algorithms to Artificial Immune System
    Jia, Bin
    Lin, Zhaowen
    Ma, Yan
    TRUSTWORTHY COMPUTING AND SERVICES (ISCTCS 2014), 2015, 520 : 221 - 228
  • [26] System-level verification methodology for advanced switch fabrics
    Sosa, J
    Montiel-Nelson, JA
    Navarro, H
    Shahdadpuri, M
    Sarmiento, R
    VLSI CIRCUITS AND SYSTEMS, 2003, 5117 : 187 - 198
  • [27] A System Dynamics Approach to Evaluate Advanced Persistent Threat Vectors
    Nicho, Mathew
    McDermott, Christopher D.
    Fakhry, Hussein
    Girija, Shini
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2023, 17 (01)
  • [28] System-level impacts of persistent main memory using a search engine
    Perez, Taciano
    Vilar Calazans, Ney Laert
    De Rose, Cesar A. F.
    MICROELECTRONICS JOURNAL, 2014, 45 (02) : 211 - 216
  • [29] Deep Reinforcement Learning for Advanced Persistent Threat Detection in Wireless Networks
    Saheed, Kazeem
    Henna, Shagufta
    2023 31ST IRISH CONFERENCE ON ARTIFICIAL INTELLIGENCE AND COGNITIVE SCIENCE, AICS, 2023,
  • [30] Analysis of high volumes of network traffic for Advanced Persistent Threat detection
    Marchetti, Mirco
    Pierazzi, Fabio
    Colajanni, Michele
    Guido, Alessandro
    COMPUTER NETWORKS, 2016, 109 : 127 - 141