Clearing the Clutter: Real-Time Program-Specific Log Consolidation for APT Detection
Xiao Han, Jiahao Xue, Zhuo Lu, Yao Liu
摘要
Enterprises are increasingly threatened by Advanced Persistent Threats (APTs), carried out by skilled adversaries and remaining undetected for months. A promising approach to detect such intrusions is to parse logs into provenance graphs that capture data dependencies. However, a major challenge with this approach is that logs can rapidly grow to enormous sizes, imposing severe memory overhead. While existing research has introduced forensic-informed methods to reduce log size, these methods achieve modest reductions and may rely on offline processing, limiting their scalability for real-time analysis.In this work, we present Nano, a real-time log reduction approach that consolidates subject dependencies into program-specific provenance. Nano introduces two novel data structures, the profile hierarchy and the access network. Rather than preserving parent-child relationships between subjects, the profile hierarchy abstracts subject origins by capturing execution relationships between programs. For subjects created through an identical execution order of programs, the access network consolidates their activities into dependencies between executing programs and system entities, while retaining dependencies between attack activities. Our evaluation, using logs from government-agency sponsored red team exercises, demonstrates that Nano can effectively detect attacks comparable to existing rule-based intrusion detection systems, while reducing logs by up to 219 times at runtime.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 被引用 253 次
- High Fidelity Data Reduction for Big Data Security Dependency AnalysesZhang Xu, Zhenyu Wu, Zhichun Li, Kangkook Jee 等CCS 2016 · 被引用 197 次
- Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceZijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang 等S&P 2024 · 被引用 125 次
- SoK: History is a Vast Early Warning System: Auditing the Provenance of System IntrusionsMuhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu 等S&P 2023
- PROGRAPHER: An Anomaly Detection System based on Provenance Graph EmbeddingFan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li 等USENIX Security 2023
