Threat detection and investigation with system-level provenance graphs: A survey

被引:40
|
作者
Li, Zhenyuan [1 ]
Chen, Qi Alfred [4 ]
Yang, Runqing [2 ]
Chen, Yan [5 ]
Ruan, Wei [3 ]
机构
[1] Zhejiang Univ, Hangzhou, Peoples R China
[2] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou, Peoples R China
[3] Zhejiang Univ, Coll Control, Hangzhou, Peoples R China
[4] Univ Calif Irvine, Dept Comp Sci, Irvine, CA USA
[5] Northwestern Univ, Dept Elect Engn & Comp Sci, Evanston, IL USA
基金
中国国家自然科学基金;
关键词
Cyber Threat; Provenance Graph; Intrusion Detection; Digital Forensic; Information Flow;
D O I
10.1016/j.cose.2021.102282
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of information technology, the border of the cyberspace gets much broader and thus also exposes increasingly more vulnerabilities to attackers. Traditional mitigation-based defence strategies are challenging to cope with the current complicated situation. Security practitioners urgently need better tools to describe and modelling attacks for defense. The provenance graph seems like an ideal method for threat modelling with powerful semantic expression ability and attacks historic correlation ability. In this paper, we firstly introduce the basic concepts about system-level provenance graph and present a typical system architecture for provenance graph-based threat detection and investigation. A comprehensive provenance graph-based threat detection system can be divided into three modules: data collection module, data management module , and threat detection modules . Each module contains several components and involves different research problems. We systematically taxonomize and compare the existing algorithms and designs involved in them. Based on these comparisons, we identify the strategy of technology selection for real-world deployment. We also provide insights and challenges about the existing work to guide future research in this area. (c) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:16
相关论文
共 50 条
  • [11] Towards System-Level Security Analysis of IoT Using Attack Graphs
    Fang, Zheng
    Fu, Hao
    Gu, Tianbo
    Hu, Pengfei
    Song, Jinyue
    Jaeger, Trent
    Mohapatra, Prasant
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (02) : 1142 - 1155
  • [12] System-level assertions: approach for electronic system-level verification
    Sohofi, Hassan
    Navabi, Zainalabedin
    IET COMPUTERS AND DIGITAL TECHNIQUES, 2015, 9 (03): : 142 - 152
  • [13] Advanced persistent threat detection via mining long-term features in provenance graphs
    Xu, Fan
    Zhao, Qinxin
    Liu, Xiaoxiao
    Wang, Nan
    Gao, Meiqi
    Wen, Xuezhi
    Zhang, Dalin
    FRONTIERS OF COMPUTER SCIENCE, 2025, 19 (10)
  • [14] A survey of design techniques for system-level dynamic power management
    Benini, L
    Bogliolo, A
    De Micheli, G
    IEEE TRANSACTIONS ON VERY LARGE SCALE INTEGRATION (VLSI) SYSTEMS, 2000, 8 (03) : 299 - 316
  • [15] Decentralised Learning in Federated Deployment Environments: A System-Level Survey
    Bellavista, Paolo
    Foschini, Luca
    Mora, Alessio
    ACM COMPUTING SURVEYS, 2021, 54 (01)
  • [16] Application Level Investigation of System-Level ESD-Induced Soft Failures
    Vora, Sandeep
    Jiang, Rui
    Vasudevan, Shobha
    Rosenbaum, Elyse
    2016 38TH ELECTRICAL OVERSTRESS/ELECTROSTATIC DISCHARGE SYMPOSIUM (EOS/ESD), 2016,
  • [17] A system-level investigation into the pharmacological mechanisms of flavor compounds in liquor
    Zhou, Wei
    Chen, Ziyi
    Zhang, Guohao
    Liu, Zhigang
    JOURNAL OF FOOD BIOCHEMISTRY, 2020, 44 (10)
  • [18] Automated Cause Analysis of Latency Outliers Using System-Level Dependency Graphs
    Patel, Sneh
    Park, Brendan
    Ezzati-Jivan, Naser
    Fournier, Quentin
    2021 IEEE 21ST INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS 2021), 2021, : 422 - 433
  • [19] SYSTEM-LEVEL AND SYSTEM PROPERTY
    NOELL, JJ
    AMERICAN SOCIOLOGICAL REVIEW, 1974, 39 (06) : 885 - 886
  • [20] SYSTEM-LEVEL DESIGN
    BOURBON, B
    COMPUTER DESIGN, 1990, 29 (23): : 19 - 21