USENIX Security2026Top-tier venue
Cutting the Fuse: Actionable APT Attack Blocking in Provenance-based IDS
Weiheng Wu, Wei Qiao, Teng Li, Yebo Feng, Zhuo Ma, Jianfeng Ma, Yang Liu
Abstract
Provenance-based Intrusion Detection Systems (PIDS) are a critical line of defense against Advanced Persistent Threats (APTs). However, their practical deployment is crippled by alert flooding; state-of-the-art PIDS focus on detection performance, outputting thousands of low-information, unactionable alerts. These outputs fail to isolate the true cause of the detector's alert and cannot provide the security operations center(SOC) with actionable blocking strategies.
To address this challenge, we propose PROVX, a novel APT defense framework designed for blocking attack steps within alerts. Unlike existing works, PROVX does not aim to merely improve attack detection performance; it is dedicated to transforming unactionable raw alerts into a core edge list for immediate review. Specifically, we introduce counterfactual explanation logic to reduce the alerts and find the minimal structural subset (i.e., the core attack edges) within an alert that determines its malicious prediction. This subset, when perturbed, can subvert the model's original prediction. The framework then applies a staged solidification strategy to enhance the precision and stability of the alert analysis. Ultimately, PROVX outputs an actionable core edge list for immediate response and blocking of critical attack steps. Experiments on DARPA datasets demonstrate that PROVX can locate key behaviors within alerts that are highly relevant to real-world attacks, and the identified core edges can flip many detector alerts under the simulated intervention used in our model-level evaluation. Furthermore, we explore and provide a preliminary validation of an alert-feedback enhancement framework, showing that PROVX's analysis results can guide model optimization in adversarial scenarios.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 93836ed2-faae-4c2b-a3d5-569cc166cb50Builds on24
- Parameterized Explainer for Graph Neural NetworkDongsheng Luo, Wei Cheng, Dongkuan Xu, Wenchao Yu et al.NeurIPS 2020 · 888 citations
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- On Explainability of Graph Neural Networks via Subgraph ExplorationsHao Yuan, Haiyang Yu, Jie Wang, Kang Li et al.ICML 2021 · 498 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 313 citations
Related papers
- Enabling Efficient Attack Investigation via Human-in-the-Loop Security AnalysisSaimon Amanuel Tsegai, Xinyu Yang, Haoyuan Liu, Peng GaoVLDB 2025 · 2 citations
- Slot: Provenance-Driven APT Detection through Graph Reinforcement LearningWei Qiao, Yebo Feng, Teng Li, Zhuo Ma et al.CCS 2025 · 1 citation
- Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral LogicWenhao Yan, Ning An, Wei Qiao, Weiheng Wu et al.AAAI 2026 · 1 citation
- Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response ToolsFeng Dong, Shaofei Li, Peng Jiang, Ding Li et al.CCS 2023 · 24 citations
- Brewing Vodka: Distilling Pure Knowledge for Lightweight Threat Detection in Audit LogsWeiheng Wu, Wei Qiao, Wenhao Yan, Bo Jiang et al.WWW 2025 · 4 citations
