返回
PathWatcher: A path-based behavior detection method for attack detection and investigation
DOI:10.1016/j.cose.2025.104563.png)
摘要
En 中文
高级持续性威胁(APT)包含复杂且隐蔽的攻击技术。由于系统审计日志能够捕获系统级进程调用并提供细粒度的日志数据,使用审计日志进行高级威胁行为的因果分析已成为一种流行的解决方案。然而,现有方案仍存在以下不足:(1)低级视图中的原始数据与高级系统行为之间的语义鸿沟,(2)告警疲劳,(3)可解释性和可推断性差。
Keyword:
Advanced Persistent Threats
System audit logs
Causal analysis
Semantic gap
Alert fatigue

