ATKHunter: Towards Automated Attack Detection by Behavior Pattern Learning
摘要
State-of-the-art research has explored various methods for intrusion detection through log analysis. However, many methods fail to detect novel attacks due to their excessive reliance on prior knowledge about attack features. Despite the introduction of various methods to uncover unknown attacks, challenges persist in data modeling and attack investigation. In this paper, we propose ATKHunter, a log analysis-supported attack detection framework based on behaviour patterns. ATKHunter has developed a novel approach for partitioning behavioural patterns and effectively embedding them. In the investigation stage, ATKHunter can directly locate attack-related entities on the provenance graph and construct concise attack stories. We evaluate ATKHunter on the DARPA dataset and the laboratory dataset. The results demonstrate that ATKHunter can detect previously unseen attacks with an F1-score of 95.79%, outperforming other advanced detection methods.