A Stream-based Query System for Efficiently Detecting Abnormal System Behaviors for Enterprise Security

03/19/2019
by   Peng Gao, et al.
0

The need for countering Advanced Persistent Threat (APT) attacks has led to the solutions that ubiquitously monitor system activities in each enterprise host, and perform timely abnormal system behavior detection over the stream of monitoring data. However, existing stream-based solutions lack explicit language constructs for expressing anomaly models that capture abnormal system behaviors, thus facing challenges in incorporating expert knowledge to perform timely anomaly detection over the large-scale monitoring data. To address these limitations, we build SAQL, a novel stream-based query system that takes as input, a real-time event feed aggregated from multiple hosts in an enterprise, and provides an anomaly query engine that queries the event feed to identify abnormal behaviors based on the specified anomaly models. SAQL provides a domain-specific query language, Stream-based Anomaly Query Language (SAQL), that uniquely integrates critical primitives for expressing major types of anomaly models. In the demo, we aim to show the complete usage scenario of SAQL by (1) performing an APT attack in a controlled environment, and (2) using SAQL to detect the abnormal behaviors in real time by querying the collected stream of system monitoring data that contains the attack traces. The audience will have the option to perform the APT attack themselves under our guidance, and interact with the system and detect the attack footprints in real time via issuing queries and checking the query results through a command-line UI.

READ FULL TEXT
research
06/25/2018

SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior Detection

Recently, advanced cyber attacks, which consist of a sequence of steps t...
research
06/06/2018

AIQL: Enabling Efficient Attack Investigation from System Monitoring Data

The need for countering Advanced Persistent Threat (APT) attacks has led...
research
10/04/2018

A Query Tool for Efficiently Investigating Risky Software Behaviors

Advanced Persistent Threat (APT) attacks are sophisticated and stealthy,...
research
10/17/2017

Internet Anomaly Detection based on Complex Network Path

Detecting the anomaly behaviors such as network failure or Internet inte...
research
04/07/2020

Challenges in Vessel Behavior and Anomaly Detection: From Classical Machine Learning to Deep Learning

The global expansion of maritime activities and the development of the A...
research
06/06/2019

Failures detection at directional drilling using real-time analogues search

One of the main challenges in the construction of oil and gas wells is t...
research
01/18/2021

Applying High-Performance Bioinformatics Tools for Outlier Detection in Log Data

Most of today's security solutions, such as security information and eve...

Please sign up or login with your details

Forgot password? Click here to reset