State-of-the-art research has explored various methods for intrusion detection through log analysis. However, many methods fail to detect novel attacks due to their excessive reliance on prior knowledge about attack features. Despite the introduction of various methods to uncover unknown attacks, challenges persist in data modeling and attack investigation. In this paper, we propose ATKHunter, a log analysis-supported attack detection framework based on behaviour patterns. ATKHunter has developed a novel approach for partitioning behavioural patterns and effectively embedding them. In the investigation stage, ATKHunter can directly locate attack-related entities on the provenance graph and construct concise attack stories. We evaluate ATKHunter on the DARPA dataset and the laboratory dataset. The results demonstrate that ATKHunter can detect previously unseen attacks with an F1-score of 95.79%, outperforming other advanced detection methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ATKHunter: Towards Automated Attack Detection by Behavior Pattern Learning

  • Yuedong Pan,
  • Lixin Zhao,
  • Chaofei Li,
  • Tao Leng,
  • Aimin Yu,
  • Lijun Cai,
  • Dan Meng

摘要

State-of-the-art research has explored various methods for intrusion detection through log analysis. However, many methods fail to detect novel attacks due to their excessive reliance on prior knowledge about attack features. Despite the introduction of various methods to uncover unknown attacks, challenges persist in data modeling and attack investigation. In this paper, we propose ATKHunter, a log analysis-supported attack detection framework based on behaviour patterns. ATKHunter has developed a novel approach for partitioning behavioural patterns and effectively embedding them. In the investigation stage, ATKHunter can directly locate attack-related entities on the provenance graph and construct concise attack stories. We evaluate ATKHunter on the DARPA dataset and the laboratory dataset. The results demonstrate that ATKHunter can detect previously unseen attacks with an F1-score of 95.79%, outperforming other advanced detection methods.