Mining Attributed Graphs for Threat Intelligence

被引:16
|
作者
Gascon, Hugo [1 ]
Grobauer, Bernd [2 ]
Schreck, Thomas [2 ]
Rist, Lukas [3 ]
Arp, Daniel [1 ]
Rieck, Konrad [1 ]
机构
[1] Tech Univ Carolo Wilhelmina Braunschweig, Braunschweig, Germany
[2] Siemens AG, Munich, Germany
[3] Symantec Corp, Tempe, AZ USA
关键词
Threat Intelligence; Advanced Persistent Threat; Graph Mining; Information Retrieval;
D O I
10.1145/3029806.3029811
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Understanding and fending off attack campaigns against organizations, companies and individuals, has become a global struggle. As today's threat actors become more determined and organized, isolated efforts to detect and reveal threats are no longer effective. Although challenging, this situation can be significantly changed if information about security incidents is collected, shared and analyzed across organizations. To this end, different exchange data formats such as STIX, CyBOX, or IODEF have been recently proposed and numerous CERTs are adopting these threat intelligence standards to share tactical and technical threat insights. However, managing, analyzing and correlating the vast amount of data available from different sources to identify relevant attack patterns still remains an open problem. In this paper we present MANTIS, a platform for threat intelligence that enables the unified analysis of different standards and the correlation of threat data trough a novel type-agnostic similarity algorithm based on attributed graphs. Its unified representation allows the security analyst to discover similar and related threats by linking patterns shared between seemingly unrelated attack campaigns through queries of different complexity. We evaluate the performance of MANTIS as an information retrieval system for threat intelligence in different experiments. In an evaluation with over 14,000 CyBOX objects, the platform enables retrieving relevant threat reports with a mean average precision of 80%, given only a single object from an incident, such as a file or an HTTP request. We further illustrate the performance of this analysis in two case studies with the attack campaigns Stuxnet and Regin.
引用
收藏
页码:15 / 22
页数:8
相关论文
共 50 条
  • [1] Mining communities and their descriptions on attributed graphs: a survey
    Martin Atzmueller
    Stephan Günnemann
    Albrecht Zimmermann
    Data Mining and Knowledge Discovery, 2021, 35 : 661 - 687
  • [2] Mining exceptional closed patterns in attributed graphs
    Anes Bendimerad
    Marc Plantevit
    Céline Robardet
    Knowledge and Information Systems, 2018, 56 : 1 - 25
  • [3] Mining communities and their descriptions on attributed graphs: a survey
    Atzmueller, Martin
    Guennemann, Stephan
    Zimmermann, Albrecht
    DATA MINING AND KNOWLEDGE DISCOVERY, 2021, 35 (03) : 661 - 687
  • [4] Mining exceptional closed patterns in attributed graphs
    Bendimerad, Anes
    Plantevit, Marc
    Robardet, Celine
    KNOWLEDGE AND INFORMATION SYSTEMS, 2018, 56 (01) : 1 - 25
  • [5] Mining credible attribute rules in dynamic attributed graphs
    He, Cheng
    Chen, Xinyang
    Chen, Guoting
    Gan, Wensheng
    Fournier-Viger, Philippe
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 246
  • [6] Mining Statistically Significant Attribute Associations in Attributed Graphs
    Lee, Jihwan
    Park, Keehwan
    Prabhakar, Sunil
    2016 IEEE 16TH INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2016, : 991 - 996
  • [7] Statistical Selection of Congruent Subspaces for Mining Attributed Graphs
    Sanchez, Patricia Iglesias
    Mueller, Emmanuel
    Laforet, Fabian
    Keller, Fabian
    Boehm, Klemens
    2013 IEEE 13TH INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2013, : 647 - 656
  • [8] Mining Attribute Evolution Rules in Dynamic Attributed Graphs
    Fournier-Viger, Philippe
    He, Ganghuan
    Lin, Jerry Chun-Wei
    Gomes, Heitor Murilo
    BIG DATA ANALYTICS AND KNOWLEDGE DISCOVERY (DAWAK 2020), 2020, 12393 : 167 - 182
  • [9] Mining significant trend sequences in dynamic attributed graphs
    Fournier-Viger, Philippe
    Cheng, Chao
    Cheng, Zhi
    Lin, Jerry Chun-Wei
    Selmaoui-Folcher, Nazha
    KNOWLEDGE-BASED SYSTEMS, 2019, 182
  • [10] MinerLSD: Efficient Local Pattern Mining on Attributed Graphs
    Atzmueller, Martin
    Soldano, Henry
    Santini, Guillaume
    Bouthinon, Dominique
    2018 18TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW), 2018, : 219 - 228