Cutting the Fuse: Actionable APT Attack Blocking in Provenance-based IDS
Weiheng Wu, Wei Qiao, Teng Li, Yebo Feng, Zhuo Ma, Jianfeng Ma, Yang Liu
摘要
Provenance-based Intrusion Detection Systems (PIDS) are a critical line of defense against Advanced Persistent Threats (APTs). However, their practical deployment is crippled by alert flooding; state-of-the-art PIDS focus on detection performance, outputting thousands of low-information, unactionable alerts. These outputs fail to isolate the true cause of the detector's alert and cannot provide the security operations center(SOC) with actionable blocking strategies.
To address this challenge, we propose PROVX, a novel APT defense framework designed for blocking attack steps within alerts. Unlike existing works, PROVX does not aim to merely improve attack detection performance; it is dedicated to transforming unactionable raw alerts into a core edge list for immediate review. Specifically, we introduce counterfactual explanation logic to reduce the alerts and find the minimal structural subset (i.e., the core attack edges) within an alert that determines its malicious prediction. This subset, when perturbed, can subvert the model's original prediction. The framework then applies a staged solidification strategy to enhance the precision and stability of the alert analysis. Ultimately, PROVX outputs an actionable core edge list for immediate response and blocking of critical attack steps. Experiments on DARPA datasets demonstrate that PROVX can locate key behaviors within alerts that are highly relevant to real-world attacks, and the identified core edges can flip many detector alerts under the simulated intervention used in our model-level evaluation. Furthermore, we explore and provide a preliminary validation of an alert-feedback enhancement framework, showing that PROVX's analysis results can guide model optimization in adversarial scenarios.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper24
- Parameterized Explainer for Graph Neural NetworkDongsheng Luo, Wei Cheng, Dongkuan Xu, Wenchao Yu 等NeurIPS 2020 · 被引用 888 次
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- On Explainability of Graph Neural Networks via Subgraph ExplorationsHao Yuan, Haiyang Yu, Jie Wang, Kang Li 等ICML 2021 · 被引用 498 次
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 被引用 317 次
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 被引用 313 次
相关 Paper
- Enabling Efficient Attack Investigation via Human-in-the-Loop Security AnalysisSaimon Amanuel Tsegai, Xinyu Yang, Haoyuan Liu, Peng GaoVLDB 2025 · 被引用 2 次
- Slot: Provenance-Driven APT Detection through Graph Reinforcement LearningWei Qiao, Yebo Feng, Teng Li, Zhuo Ma 等CCS 2025 · 被引用 1 次
- Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral LogicWenhao Yan, Ning An, Wei Qiao, Weiheng Wu 等AAAI 2026 · 被引用 1 次
- Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response ToolsFeng Dong, Shaofei Li, Peng Jiang, Ding Li 等CCS 2023 · 被引用 24 次
- Brewing Vodka: Distilling Pure Knowledge for Lightweight Threat Detection in Audit LogsWeiheng Wu, Wei Qiao, Wenhao Yan, Bo Jiang 等WWW 2025 · 被引用 4 次
