Knowledge Enrichment by Fusing Representations for Malware Threat Intelligence and Behavior

Knowledge Enrichment by Fusing Representations for Malware Threat Intelligence and Behavior
复制标题

DOI:
10.1109/isi49825.2020.9280512
复制
发表时间:
2020-11
期刊:
2020 IEEE International Conference on Intelligence and Security Informatics (ISI)
影响因子:
--
通讯作者:
Aritran Piplai;Sudip Mittal;Mahmoud Abdelsalam;Maanak Gupta;A. Joshi;Tim Finin-
Aritran Piplai;Sudip Mittal;Mahmoud Abdelsalam;Maanak Gupta;A. Joshi;Tim Finin-
中科院分区:
其他
文献类型:
--
作者:
Aritran Piplai;Sudip Mittal;Mahmoud Abdelsalam;Maanak Gupta;A. Joshi;Tim Finin-

文献摘要

被引文献

相似文献

安全工程师和研究人员利用他们不同的知识和判断力来识别系统中存在的恶意软件。有时,他们也可能使用先前提取的知识和关于已知攻击的可用网络威胁情报(CTI)来建立模式。为了在这个过程中提供帮助,他们需要了解映射到可用CTI的恶意软件行为。这样的映射丰富了我们的表示,也有助于验证信息。在本文中,我们描述了如何检索恶意软件样本并在本地系统中执行它们。跟踪的恶意软件行为在我们的网络安全知识图(CKG)中表示,因此安全专业人员可以根据图中呈现的行为信息进行推理,并与该信息进行类比。我们还将行为信息与从CTI来源(如技术报告和博客)中提取的关于同一恶意软件的文本中的知识合并,以显着提高CKG的推理能力。
Security engineers and researchers use their disparate knowledge and discretion to identify malware present in a system. Sometimes, they may also use previously extracted knowledge and available Cyber Threat Intelligence (CTI) about known attacks to establish a pattern. To aid in this process, they need knowledge about malware behavior mapped to the available CTI. Such mappings enrich our representations and also helps verify the information. In this paper, we describe how we retrieve malware samples and execute them in a local system. The tracked malware behavior is represented in our Cybersecurity Knowledge Graph (CKG), so that a security professional can reason with behavioral information present in the graph and draw parallels with that information. We also merge the behavioral information with knowledge extracted from the text in CTI sources like technical reports and blogs about the same malware to improve the reasoning capabilities of our CKG significantly.