arrow
Return

TeRed: Normal Behavior-Based Efficient Provenance Graph Reduction for Large-Scale Attack Forensics

delete2025-01-01
delete0
PRE
AI
X
Xiaoxiang Li
X
Xinyu Jiang
万海 (Hai Wan)
赵曦滨 (Xibin Zhao)
DOI:10.1109/TIFS.2025.3601381delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
System intrusions, particularly Advanced Persistent Threats (APTs), pose significant threats to enterprises and organizations. Provenance graph-based attack detection and investigation methods are crucial for defending against these intrusions. To detect various attacks, security systems collect comprehensive operating system event data, resulting in massive provenance graphs that increase storage costs and complicate analysis and querying. Efficiently optimizing these provenance graphs has thus become a core issue. However, existing data reduction methods often mistakenly delete critical security information, significantly impacting attack detection and investigation. This paper introduces TeRed, a novel method for reducing provenance graphs based on normal behavior patterns. Our approach employs unit tests to learn the system’s normal behavior patterns, which are then used to streamline the provenance graph. Experiments on five datasets show that our method reduces the provenance graph while preserving all attack-related information. Importantly, it does not compromise attack detection and investigation, showcasing significant advantages over other data reduction techniques.
Keywords:
Data reduction
provenance graph
template mining
intrusion detection
attack investigation

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

T
tsinghua university
Scholars:
11.7W
Papers: 10.0W
Citations: 137