POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting

POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting
复制标题

DOI:
10.1145/3319535.3363217
复制
发表时间:
2019-09
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Sadegh M. Milajerdi;Birhanu Eshete;Rigel Gjomemo;V. Venkatakrishnan
Sadegh M. Milajerdi;Birhanu Eshete;Rigel Gjomemo;V. Venkatakrishnan
中科院分区:
其他
文献类型:
--
作者:
Sadegh M. Milajerdi;Birhanu Eshete;Rigel Gjomemo;V. Venkatakrishnan

文献摘要

被引文献

相似文献

网络威胁情报(CTI)被用于搜索可能长期危害企业网络而未被发现的攻击指标。为了进行更有效的分析,CTI开放标准纳入了描述性关系,显示了指标或可观测量如何相互关联。然而,这些关系要么在信息收集中被完全忽视,要么不用于威胁搜索。在本文中,我们提出了一个系统,称为POIROT,它使用这些相关性来揭示一个成功的攻击活动的步骤。我们使用内核审计作为一个可靠的来源,涵盖了所有的因果关系和系统实体之间的信息流和模型威胁狩猎作为一个不精确的图形模式匹配问题。我们的技术方法是基于一种新的相似性度量,该度量评估了由CTI相关性构建的查询图和由内核审计日志记录构建的起源图之间的对齐。我们根据公开发布的真实事件报告以及DARPA设计的对抗性攻击报告评估POIROT,其中包括针对不同操作系统平台(如Linux、FreeBSD和Windows)的10次不同攻击活动。我们的评估结果表明,POIROT能够搜索包含数百万个节点的内部图,并在几分钟内查明攻击,结果表明CTI相关性可用作威胁狩猎的强大和可靠的工件。
Cyber threat intelligence (CTI) is being used to search for indicators of attacks that might have compromised an enterprise network for a long time without being discovered. To have a more effective analysis, CTI open standards have incorporated descriptive relationships showing how the indicators or observables are related to each other. However, these relationships are either completely overlooked in information gathering or not used for threat hunting. In this paper, we propose a system, called POIROT, which uses these correlations to uncover the steps of a successful attack campaign. We use kernel audits as a reliable source that covers all causal relations and information flows among system entities and model threat hunting as an inexact graph pattern matching problem. Our technical approach is based on a novel similarity metric which assesses an alignment between a query graph constructed out of CTI correlations and a provenance graph constructed out of kernel audit log records. We evaluate POIROT on publicly released real-world incident reports as well as reports of an adversarial engagement designed by DARPA, including ten distinct attack campaigns against different OS platforms such as Linux, FreeBSD, and Windows. Our evaluation results show that POIROT is capable of searching inside graphs containing millions of nodes and pinpoint the attacks in a few minutes, and the results serve to illustrate that CTI correlations could be used as robust and reliable artifacts for threat hunting.