WATSON: Abstracting Behaviors from Audit Logs via Aggregation of Contextual Semantics
Jun Zeng, Zheng Leong Chua, Yinfang Chen, Kaihang Ji, Zhenkai Liang, Jian Mao
Abstract
—Endpoint monitoring solutions are widely deployed in today’s enterprise environments to support advanced attack detection and investigation. These monitors continuously record system-level activities as audit logs and provide deep visibility into security incidents. Unfortunately, to recognize behaviors of interest and detect potential threats, cyber analysts face a semantic gap between low-level audit events and high-level system behaviors. To bridge this gap, existing work largely matches streams of audit logs against a knowledge base of rules that describe behaviors. However, specifying such rules heavily relies on expert knowledge. In this paper, we present W ATSON , an automated approach to abstracting behaviors by inferring and aggregating the semantics of audit events. W ATSON uncovers the semantics of events through their usage context in audit logs. By extracting behaviors as connected system operations, W ATSON then combines event semantics as the representation of behaviors. To reduce analysis workload, W ATSON further clusters semanti- cally similar behaviors and distinguishes the representatives for analyst investigation. In our evaluation against both benign and malicious behaviors, W ATSON exhibits high accuracy for behavior abstraction. Moreover, W ATSON can reduce analysis workload by two orders of magnitude for attack investigation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 090dae55-ff42-4c5e-94de-ad29d57d3643Cited by top-tier papers21
- SHADEWATCHER: Recommendation-guided Cyber Threat Analysis using System Audit RecordsJun Zeng, Xiang Wang, Jiahao Liu, Yinfang Chen et al.S&P 2022 · 187 citations
- Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation LearningMati Ur Rehman, Hadi Ahmadi, Wajih Ul HassanS&P 2024 · 104 citations
- MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation LearningZian Jia, Yun Xiong, Yuhong Nan, Yao Zhang et al.USENIX Security 2024 · 92 citations
- ProvG-Searcher: A Graph Representation Learning Approach for Efficient Provenance Graph SearchEnes Altinisik, Fatih Deniz, Hüsrev Taha SencarCCS 2023 · 32 citations
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 31 citations
Builds on25
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
- Log2vec: A Heterogeneous Graph Embedding Based Approach for Detecting Cyber Threats within EnterpriseFucheng Liu, Yu Wen, Dongxue Zhang, Xihe Jiang et al.CCS 2019 · 314 citations
Related papers
- ANTEATER: A Filter-then-Scrutinize Architecture for End-to-End Attack InvestigationYiming Ren, Haoqiang Wang, Linghao Li, Haoyang Chen et al.SIGMOD 2026
- ATLAS: A Sequence-based Learning Approach for Attack InvestigationAbdulellah Alsaheel, Yuhong Nan, Shiqing Ma, Le Yu et al.USENIX Security 2021 · 256 citations
- SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior DetectionPeng Gao, Xusheng Xiao, Ding Li, Zhichun Li et al.USENIX Security 2018 · 122 citations
- Interpretable and Robust Behavior Abstraction via Environment-Disentangled Heterogeneous GraphZhibin Ni, Hai Wan, Xibin ZhaoAAAI 2026
- WatchLog: Efficient and Interpretable Event Reasoning for Endpoint Detection and Response Logs with Multimodal LLMsHongyi Zhou, Jianfeng Pan, Min Peng, Shaomang Huang et al.ICML 2026
