arrow
返回

MEGR-APT: A Memory-Efficient APT Hunting System Based on Attack Representation Learning

delete2024-01-01
delete0
PRE
AI
A
Ahmed H. Aly *
S
Shahrear Iqbal
A
Amr Youssef
M
Mansour, Essam
DOI:10.1109/TIFS.2024.3396390delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The stealthy and persistent nature of Advanced Persistent Threats (APTs) makes them one of the most challenging cyber threats to uncover. Several systems adopted the development of provenance-graph-based security solutions to capture this persistent nature. Provenance graphs (PGs) represent system audit logs by connecting system entities using causal relations and information flows. Hunting APTs demands the processing of ever-growing large-scale PGs of audit logs for a wide range of activities over months or years, i.e., multi-terabyte graphs. Existing APT hunting systems are typically memory-based, which suffers colossal memory consumption, or disk-based, which suffers from performance hits. Therefore, these systems are hard to scale in terms of graph size or time performance. In this paper, we propose MEGR-APT, a scalable APT hunting system to discover suspicious subgraphs matching an attack scenario (query graph) published in Cyber Threat Intelligence (CTI) reports. MEGR-APT hunts APTs in a twofold process: (i) memory-efficient extraction of suspicious subgraphs as search queries over a graph database, and (ii) fast subgraph matching based on graph neural network (GNN) and our effective attack representation learning. We compared MEGR-APT with state-of-the-art (SOTA) APT systems using popular APT benchmarks, such as DARPA TC3 and OpTC. We also tested it using a real enterprise dataset. MEGR-APT achieves an order of magnitude reduction in memory consumption while achieving comparable performance to SOTA in terms of time and accuracy.
Keyword:
Representation learning
Memory management
Resource description framework
Load modeling
Cyber threat intelligence
Databases
Costs
GNN-based APT hunting
provenance graphs

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

C
concordia university - canada
学者数:
8.0K
论文数: 8.9K
被引数: 4
N
National Research Council Canada
学者数:
7.9K
论文数: 7.9K
被引数: 6.8K
引用论文

引用论文

Development and application of competitive elisa assays for rat LH and FSH
err1999-04-01
err0
PREAI
errA Pappa; K Seferiadis; M Marselos; O Tsolas; I.E Messinis
err分享
err收藏
Use of Recombinant Iron‐Superoxide Dismutase as A Marker of Nitrative Stress
err2008-01-01
err0
PREAI
errEstíbaliz Larrainzar; Estíbaliz Urarte; Iñigo Auzmendi; Idoia Ariz; Cesar Arrese‐Igor; Esther M. González; Jose F. Moran
err分享
err收藏
Provenance-based Intrusion Detection Systems: A Survey
err2022-12-15
err35
errOAAI
errZipperle, Michael; Gottwalt, Florian; Chang, Elizabeth; Dillon, Tharam
err分享
err收藏
err分享
err收藏
On the exact computation of the graph edit distance
err2020-06-01
err48
PREAI
errBlumenthal, David B.; Gamper, Johann
err分享
err收藏
学者 查看更多内容