A framework for comprehensible multi-modal detection of cyber threats

11/10/2021
by   Jan Kohout, et al.
0

Detection of malicious activities in corporate environments is a very complex task and much effort has been invested into research of its automation. However, vast majority of existing methods operate only in a narrow scope which limits them to capture only fragments of the evidence of malware's presence. Consequently, such approach is not aligned with the way how the cyber threats are studied and described by domain experts. In this work, we discuss these limitations and design a detection framework which combines observed events from different sources of data. Thanks to this, it provides full insight into the attack life cycle and enables detection of threats that require this coupling of observations from different telemetries to identify the full scope of the incident. We demonstrate applicability of the framework on a case study of a real malware infection observed in a corporate network.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/04/2023

MalwareDNA: Simultaneous Classification of Malware, Malware Families, and Novel Malware

Malware is one of the most dangerous and costly cyber threats to nationa...
research
03/13/2023

A data-driven analysis of UK cyber defence

Our research addresses the question: What are the conditions of the UK's...
research
11/23/2020

On a Bayesian Approach to Malware Detection and Classification through n-gram Profiles

Detecting and correctly classifying malicious executables has become one...
research
01/25/2020

A Review of Cybersecurity Incidents in the Water Sector

This study presents a critical review of disclosed, documented, and mali...
research
10/30/2018

Finding Cryptocurrency Attack Indicators Using Temporal Logic and Darkweb Data

With the recent prevalence of darkweb/deepweb (D2web) sites specializing...
research
03/13/2021

Defining, Evaluating, Preparing for and Responding to a Cyber Pearl Harbor

Despite not having a clear meaning, public perception and awareness make...
research
07/29/2021

Zooming Into the Darknet: Characterizing Internet Background Radiation and its Structural Changes

Network telescopes or "Darknets" provide a unique window into Internet-w...

Please sign up or login with your details

Forgot password? Click here to reset