kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Publications (2 of 2) Show all publications
Sachidananda, V., Patil, R., Sachdeva, A., Lam, K. Y. & Yang, L. (2023). APTer: Towards the Investigation of APT Attribution. In: Proceedings - 2023 IEEE Conference on Dependable and Secure Computing, DSC 2023: . Paper presented at 6th IEEE Conference on Dependable and Secure Computing, DSC 2023, Tampa, United States of America, Nov 7 2023 - Nov 9 2023. Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>APTer: Towards the Investigation of APT Attribution
Show others...
2023 (English)In: Proceedings - 2023 IEEE Conference on Dependable and Secure Computing, DSC 2023, Institute of Electrical and Electronics Engineers (IEEE) , 2023Conference paper, Published paper (Refereed)
Abstract [en]

The rise of Advanced Persistent Threats (APTs) in recent years has sparked widespread concern in the cyber domain. APT-based cyberattacks are often stealthy, multistaged, slow-moving, low-profile, and time-consuming. Furthermore, these attacks consist of a series of steps, each employing a different technique variation. Consequently, most existing approaches are inadequate for analyzing the behavior of such attacks effectively. To prevent potential compromises, a proactive APT defense strategy that can identify potential APT stages and attribute them to a specific APT group is required. Therefore, for both public and private organizations, the correlation and attribution of these attacks are crucial. In this paper, we propose APTer, a preliminary effort towards the archetype of APT attribution. The first aim of the research is to correlate multiple stages of APTs based on threat alerts. To define and correlate the APT stages, APTer first eliminates redundant threat alerts and clusters the remaining ones. Second, APTer uses a novel APT stage prediction mechanism to forecast future APT phases. We have developed a prediction model to determine the next APT stages. Finally, APTer attributes the identified and predicted stages to a particular APT group. APT attribution aims to find MITRE ATTCK Tools, Tactics, and Procedures (TTPs) that indicate possible threats by a specific group correlated with the MITRE ATTCK knowledge base. Additionally, we perform mapping of Common Vulnerability Exploits (CVEs) to MITRE ATTCK to provide additional knowledge about existing vulnerabilities that can be mapped to the MITRE ATTCK technique. We have evaluated our work on real-world datasets from Third Party. Our results show that APTer can correlate, predict, attribute, and map with high accuracy of 97.3% and low false-positive rates of 2.1%.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2023
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-342652 (URN)10.1109/DSC61021.2023.10354155 (DOI)2-s2.0-85182271950 (Scopus ID)
Conference
6th IEEE Conference on Dependable and Secure Computing, DSC 2023, Tampa, United States of America, Nov 7 2023 - Nov 9 2023
Note

Part of ISBN 9798350382112

QC 20240125

Available from: 2024-01-25 Created: 2024-01-25 Last updated: 2024-07-01Bibliographically approved
Sachidananda, V., Patil, R., Peng, H., Yang, L. & Lam, K. Y. (2023). ThreatLand: Extracting Intelligence from Audit Logs via NLP methods. In: 2023 20th Annual International Conference on Privacy, Security and Trust, PST 2023: . Paper presented at 20th Annual International Conference on Privacy, Security and Trust, PST 2023, Hybrid, Copenhagen, Denmark, Aug 21 2023 - Aug 23 2023. Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>ThreatLand: Extracting Intelligence from Audit Logs via NLP methods
Show others...
2023 (English)In: 2023 20th Annual International Conference on Privacy, Security and Trust, PST 2023, Institute of Electrical and Electronics Engineers (IEEE) , 2023Conference paper, Published paper (Refereed)
Abstract [en]

Threat intelligence and hunting using various logs has evolved into a crucial component of remaining aware of the ever-changing threat landscape. Given the critical need to extract useful intelligence from logs, existing techniques either focus exclusively on isolated records, ignoring correlation and the overall threat scenario, or require significant effort to filter and correlate threat records. Additionally, searching for and matching threat behaviors in logs often involves non-trivial human query construction, impeding fast threat hunting. To address this gap, we present ThreatLand, a system that extracts highlevel intelligence and structured threat patterns from audit logs automatically. ThreatLand is composed of three components (1) A lightweight and accurate NLP pipeline that extracts structured meta-data from alert descriptions and generates a heterogeneous graph that depicts the entire threat scenario. (2) A query execution engine that is both fast and efficient, based on a graphical database. (3) A graphical user interface (GUI) that offers various sorts of interactivity to aid intelligence exploration.We have evaluated the ThreatLand over the dataset containing 9240 real-time EDR alerts collected for the threat events over an enterprise setup in the lab. As a result, ThreatLand presents high-level insights from the alert logs and extracts the valuable threat patterns.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2023
Keywords
attack patterns, graph database, Threat alert, threat intelligence
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-341614 (URN)10.1109/PST58708.2023.10320173 (DOI)001108746000045 ()2-s2.0-85179547673 (Scopus ID)
Conference
20th Annual International Conference on Privacy, Security and Trust, PST 2023, Hybrid, Copenhagen, Denmark, Aug 21 2023 - Aug 23 2023
Note

Part of ISBN 9798350313871

QC 20231228

Available from: 2023-12-28 Created: 2023-12-28 Last updated: 2024-01-16Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0003-0479-6766

Search in DiVA

Show all publications