TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning
Mingqi Lv, Hongzhe Gao, Xuebo Qiu, Tieming Chen, Tiantian Zhu, Jinyin Chen, Shouling Ji
摘要
APT (Advanced Persistent Threat) with the characteristics of persistence, stealth, and diversity is one of the greatest threats against cyber-infrastructure. As a countermeasure, existing studies leverage provenance graphs to capture the complex relations between system entities in a host for effective APT detection. In addition to detecting single attack events as most existing work does, understanding the tactics / techniques (e.g., Kill-Chain, ATT&CK) applied to organize and accomplish the APT attack campaign is also important for security operations. Existing studies try to manually design a set of rules to map low-level system events to high-level APT tactics / techniques. However, the rule based methods are coarse-grained and lack generalization ability. Thus, they can only recognize APT tactics and have difficulty in identifying APT techniques. They also cannot adapt to mutant behaviors of existing APT tactics / techniques. In this paper, we propose TREC, the first attempt to recognize APT tactics / techniques from provenance graphs by exploiting deep learning techniques. To address the "needle in a haystack" problem, TREC segments small and compact subgraphs covering individual APT technique instances from a large provenance graph
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance AnalysisYuhan Meng, Shaofei Li, Jiaping Gui, Peng Jiang 等NDSS 2026 · 被引用 8 次
- APT-CGLP: Advanced Persistent Threat Hunting via Contrastive Graph-Language Pre-TrainingXuebo Qiu, Mingqi Lv, Yimei Zhang, Tieming Chen 等KDD 2026
- A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global TrendsShakhzod Yuldoshkhujaev, Mijin Jeon, Doowon Kim, Nick Nikiforakis 等CCS 2025
- NEXUS: Towards Accurate and Scalable Mapping between Vulnerabilities and Attack TechniquesEhsan Khodayarseresht, Suryadipta Majumdar, Serguei A. Mokhov, Mourad DebbabiNDSS 2026
它引用的顶会 Paper12
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen 等NDSS 2019 · 被引用 411 次
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 被引用 317 次
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete 等USENIX Security 2017 · 被引用 291 次
- ATLAS: A Sequence-based Learning Approach for Attack InvestigationAbdulellah Alsaheel, Yuhong Nan, Shiqing Ma, Le Yu 等USENIX Security 2021 · 被引用 256 次
相关 Paper
- DISTDET: A Cost-Effective Distributed Cyber Threat Detection SystemFeng Dong, Liu Wang, Xu Nie, Fei Shao 等USENIX Security 2023
- Slot: Provenance-Driven APT Detection through Graph Reinforcement LearningWei Qiao, Yebo Feng, Teng Li, Zhuo Ma 等CCS 2025 · 被引用 1 次
- HyperDetector: Advanced Persistent Threat Detection via Hypergraph Neural Networks with Enhanced Global PerceptionZiyue Wu, Nan Wang, Jiqiang Liu, Hairong Dong 等WWW 2026
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 被引用 2 次
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens 等NDSS 2020
