Clearing the Clutter: Real-Time Program-Specific Log Consolidation for APT Detection
Xiao Han, Jiahao Xue, Zhuo Lu, Yao Liu
Abstract
Enterprises are increasingly threatened by Advanced Persistent Threats (APTs), carried out by skilled adversaries and remaining undetected for months. A promising approach to detect such intrusions is to parse logs into provenance graphs that capture data dependencies. However, a major challenge with this approach is that logs can rapidly grow to enormous sizes, imposing severe memory overhead. While existing research has introduced forensic-informed methods to reduce log size, these methods achieve modest reductions and may rely on offline processing, limiting their scalability for real-time analysis.In this work, we present Nano, a real-time log reduction approach that consolidates subject dependencies into program-specific provenance. Nano introduces two novel data structures, the profile hierarchy and the access network. Rather than preserving parent-child relationships between subjects, the profile hierarchy abstracts subject origins by capturing execution relationships between programs. For subjects created through an identical execution order of programs, the access network consolidates their activities into dependencies between executing programs and system entities, while retaining dependencies between attack activities. Our evaluation, using logs from government-agency sponsored red team exercises, demonstrates that Nano can effectively detect attacks comparable to existing rule-based intrusion detection systems, while reducing logs by up to 219 times at runtime.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f20ba640-c07e-4194-a830-f3f071d40dc7Related papers
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 253 citations
- High Fidelity Data Reduction for Big Data Security Dependency AnalysesZhang Xu, Zhenyu Wu, Zhichun Li, Kangkook Jee et al.CCS 2016 · 197 citations
- Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceZijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang et al.S&P 2024 · 125 citations
- SoK: History is a Vast Early Warning System: Auditing the Provenance of System IntrusionsMuhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu et al.S&P 2023
- PROGRAPHER: An Anomaly Detection System based on Provenance Graph EmbeddingFan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li et al.USENIX Security 2023
