USENIX Security2021Top-tier venue
SIGL: Securing Software Installations Through Deep Graph Learning
Xueyuan Han, Xiao Yu, Thomas F. J.-M. Pasquier, Ding Li, Junghwan Rhee, James W. Mickens, Margo I. Seltzer, Haifeng Chen
Abstract
Many users implicitly assume that software can only be exploited after it is installed. However, recent supply-chain attacks demonstrate that application integrity must be ensured during installation itself. We introduce SIGL, a new tool for detecting malicious behavior during software installation. SIGL collects traces of system call activity, building a data provenance graph that it analyzes using a novel autoencoder architecture with a graph long short-term memory network (graph LSTM) for the encoder and a standard multilayer perceptron for the decoder. SIGL flags suspicious installations as well as the specific installation-time processes that are likely to be malicious. Using a test corpus of 625 malicious installers containing real-world malware, we demonstrate that SIGL has a detection accuracy of 96%, outperforming similar systems from industry and academia by up to 87% in precision and recall and 45% in accuracy. We also demonstrate that SIGL can pinpoint the processes most likely to have triggered malicious behavior, works on different audit platforms and operating systems, and is robust to training data contamination and adversarial attack. It can be used with application-specific models, even in the presence of new software versions, as well as application-agnostic meta-models that encompass a wide range of applications and installers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4aeefcc5-0f71-4289-9440-db4a336e44cfCited by top-tier papers22
- SHADEWATCHER: Recommendation-guided Cyber Threat Analysis using System Audit RecordsJun Zeng, Xiang Wang, Jiahao Liu, Yinfang Chen et al.S&P 2022 · 187 citations
- Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceZijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang et al.S&P 2024 · 125 citations
- Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation LearningMati Ur Rehman, Hadi Ahmadi, Wajih Ul HassanS&P 2024 · 104 citations
- MAGIC: Detecting Advanced Persistent Threats via Masked Graph Representation LearningZian Jia, Yun Xiong, Yuhong Nan, Yao Zhang et al.USENIX Security 2024 · 92 citations
- R-CAID: Embedding Root Cause Analysis within Provenance-based Intrusion DetectionAkul Goyal, Gang Wang, Adam BatesS&P 2024 · 40 citations
Builds on7
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete et al.USENIX Security 2017 · 291 citations
- Attacking Graph-based Classification via Manipulating the Graph StructureBinghui Wang, Neil Zhenqiang GongCCS 2019 · 175 citations
- A Restricted Black-Box Adversarial Framework Towards Attacking Graph Embedding ModelsHeng Chang, Yu Rong, Tingyang Xu, Wenbing Huang et al.AAAI 2020 · 171 citations
- SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior DetectionPeng Gao, Xusheng Xiao, Ding Li, Zhichun Li et al.USENIX Security 2018 · 122 citations
Related papers
- PROGRAPHER: An Anomaly Detection System based on Provenance Graph EmbeddingFan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li et al.USENIX Security 2023
- ProfMal: Detecting Malicious NPM Packages by the Synergy between Static and Dynamic AnalysisYiheng Huang, Wen Zheng, Susheng Wu, Bihuan Chen et al.ASE 2025 · 2 citations
- ORTHRUS: Achieving High Quality of Attribution in Provenance-based Intrusion Detection SystemsBaoxiang Jiang, Tristan Bilot, Nour El Madhoun, Khaldoun Al Agha et al.USENIX Security 2025
- MalGraph: Hierarchical Graph Neural Networks for Robust Windows Malware DetectionXiang Ling, Lingfei Wu, Wei Deng, Zhenqing Qu et al.INFOCOM 2022 · 47 citations
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens et al.NDSS 2020
