APM: An Attack Path-based Method for APT Attack Detection on Few-Shot Learning

被引:0
|
作者
Li, Jiacheng [1 ]
Li, Tong [1 ]
Zhang, Runzi [2 ]
Wu, Di [1 ]
Yue, Hao [1 ]
Yang, Zhen [1 ]
机构
[1] Beijing Univ Technol, Fac Informat Technol, Beijing, Peoples R China
[2] NSFOCUS Technol Grp Co Ltd, Beijing, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
attack detection; attack path; provenance graph; few-shot learning;
D O I
10.1109/TrustCom60117.2023.00025
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advanced persistent threat (APT) attack leverages various intelligence-gathering techniques to obtain sensitive and critical information, imposing increasing threats to modern software enterprises. However, due to the persistent presence of APT attacks, it is difficult to effectively analyze a large amount of audit data for detecting such attacks, especially for small and medium-sized enterprises (SMEs). This limitation hinders security operation centers (SOC) from promptly handling APT attacks. In this paper, we propose an attack path-based method (APM) for APT attack detection on few-shot learning. Specifically, APM first identifies candidate malicious entities from the provenance graph, contributing to the completion of the missing attack paths. Secondly, we propose a systematic method to exploit potential attack behaviors in the attack path based on the identified candidate malicious entities. We evaluate APM through five APT attacks in realistic environments. Compared to existing baselines, the precision, recall, and F1-score of APM for attack detection increased by 0.28%, 1.64%, and 1.13%, respectively. The results show that our proposal can outperform baseline approaches and effectively detect APT attacks based on few-shot learning.
引用
收藏
页码:10 / 19
页数:10
相关论文
共 50 条
  • [1] Few-shot website fingerprinting attack
    Chen, Mantun
    Wang, Yongjun
    Xu, Hongzuo
    Zhu, Xiatian
    COMPUTER NETWORKS, 2021, 198
  • [2] GDE model: A variable intrusion detection model for few-shot attack
    Yan, Yu
    Yang, Yu
    Shen, Fang
    Gao, Minna
    Gu, Yuheng
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2023, 35 (10)
  • [3] Few-shot Website Fingerprinting attack with Meta-Bias Learning
    Chen, Mantun
    Wang, Yongjun
    Zhu, Xiatian
    PATTERN RECOGNITION, 2022, 130
  • [4] Classifying attack traffic in IoT environments via few-shot learning
    Bovenzi, Giampaolo
    Di Monda, Davide
    Montieri, Antonio
    Persico, Valerio
    Pescape, Antonio
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 83
  • [5] Few Edges are Enough: Few-Shot Network Attack Detection with Graph Neural Networks
    Bilot, Tristan
    El Madhoun, Nour
    Al Agha, Khaldoun
    Zouaoui, Anis
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2024, 2024, 14977 : 257 - 276
  • [6] Space Decoupled Prototype Learning for Few-Shot Attack Detection in Cyber-Physical Systems
    Sun, Haili
    Huang, Yan
    Zhou, Chunjie
    Han, Lansheng
    Liu, Hongle
    Chen, Juan
    Li, Xin
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (10) : 12350 - 12362
  • [7] Insulator Anomaly Detection Method Based on Few-Shot Learning
    Wang, Zhaoyang
    Gao, Qiang
    Li, Dong
    Liu, Junjie
    Wang, Hongwei
    Yu, Xiao
    Wang, Yipin
    IEEE ACCESS, 2021, 9 : 94970 - 94980
  • [8] Few-shot website fingerprinting attack with cluster adaptation
    Zhou, Qiang
    Wang, Liangmin
    Zhu, Huijuan
    Lu, Tong
    COMPUTER NETWORKS, 2023, 229
  • [9] Few-Shot Website Fingerprinting Attack with Data Augmentation
    Chen, Mantun
    Wang, Yongjun
    Qin, Zhiquan
    Zhu, Xiatian
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [10] TrafficSiam: More Realistic Few-shot Website Fingerprinting Attack with Contrastive Learning
    Wang, Shangdong
    Wang, Zhiliang
    Li, Chenglong
    Han, Dongqi
    Yang, Jiahai
    Zhang, Hui
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,