A baseline for unsupervised advanced persistent threat detection in system-level provenance

06/17/2019
by   Ghita Berrada, et al.
0

Advanced persistent threats (APT) are stealthy, sophisticated, and unpredictable cyberattacks that can steal intellectual property, damage critical infrastructure, or cause millions of dollars in damage. Detecting APTs by monitoring system-level activity is difficult because manually inspecting the high volume of normal system activity is overwhelming for security analysts. We evaluate the effectiveness of unsupervised batch and streaming anomaly detection algorithms over multiple gigabytes of provenance traces recorded on four different operating systems to determine whether they can detect realistic APT-like attacks reliably and efficiently. This report is the first detailed study of the effectiveness of generic unsupervised anomaly detection techniques in this setting.

READ FULL TEXT
research
05/20/2021

A Rule Mining-Based Advanced Persistent Threats Detection System

Advanced persistent threats (APT) are stealthy cyber-attacks that are ai...
research
11/28/2022

A Study of Representational Properties of Unsupervised Anomaly Detection in Brain MRI

Anomaly detection in MRI is of high clinical value in imaging and diagno...
research
04/06/2023

TBDetector:Transformer-Based Detector for Advanced Persistent Threats with Provenance Graph

APT detection is difficult to detect due to the long-term latency, cover...
research
05/03/2022

ARCADE: Adversarially Regularized Convolutional Autoencoder for Network Anomaly Detection

As the number of heterogenous IP-connected devices and traffic volume in...
research
04/17/2020

Unsupervised crop anomaly detection at the parcel-level using optical and SAR images: application to wheat and rapeseed crops

This paper proposes a generic approach for crop anomaly detection at the...
research
04/22/2020

Advanced Persistent Threat: Detection and Defence

The critical assessment presented within this paper explores existing re...
research
08/30/2021

Thermal Management in Large Data Centers: Security Threats and Mitigation

Data centres are experiencing significant growth in their scale, especia...

Please sign up or login with your details

Forgot password? Click here to reset