TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning
At a glance
- Citations
- 23
- References
- 17
- Comments
- 0
Abstract
APT (Advanced Persistent Threat) with the characteristics of persistence, stealth, and diversity is one of the greatest threats against cyber-infrastructure. As a countermeasure, existing studies leverage provenance graphs to capture the complex relations between system entities in a host for effective APT detection. In addition to detecting single attack events as most existing work does, understanding the tactics / techniques (e.g., Kill-Chain, ATT&CK) applied to organize and accomplish the APT attack campaign is also important for security operations. Existing studies try to manually design a set of rules to map low-level system events to high-level APT tactics / techniques. However, the rule based methods are coarse-grained and lack generalization ability. Thus, they can only recognize APT tactics and have difficulty in identifying APT techniques. They also cannot adapt to mutant behaviors of existing APT tactics / techniques.
Publication details
- DOI
- 10.1145/3658644.3690221
- OpenAlex
- W4392182086
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.