Creating Cybersecurity Knowledge Graphs From Malware After Action Reports

Creating Cybersecurity Knowledge Graphs From Malware After Action Reports
复制标题

DOI:
10.1109/access.2020.3039234
复制
发表时间:
2020-10
期刊:
影响因子:
3.9
通讯作者:
Aritran Piplai;Sudip Mittal;A. Joshi;Tim Finin-;James Holt;Richard Zak
Aritran Piplai;Sudip Mittal;A. Joshi;Tim Finin-;James Holt;Richard Zak
中科院分区:
计算机科学3区
文献类型:
--
作者:
Aritran Piplai;Sudip Mittal;A. Joshi;Tim Finin-;James Holt;Richard Zak

文献摘要

相似文献

行动后报告(AARs)提供了对网络事件的深刻分析。从这些来源提取网络知识将为安全分析人员提供可靠的信息,他们可以利用这些信息来检测或发现表明网络攻击的模式。本文描述了一个从aar中提取信息的系统,通过将相似实体融合在一起来聚合提取的信息,并将提取的信息表示为网络安全知识图(CKG)。我们通过构建一个名为“恶意软件实体提取器”(Malware entity Extractor, MEE)的定制命名实体识别器来提取实体。然后,我们建立一个神经网络来预测成对的“恶意软件实体”如何相互关联。当我们预测了实体对及其之间的关系时,我们在CKG中断言“实体-关系集”。我们的下一步是融合类似的实体,以改善我们的CKG。这种融合有助于表示从多个文档和报告中提取的情报。融合的CKG拥有来自多个aar的知识,并从单独的报告中提取实体之间的关系。由于这种融合,安全分析人员可以在融合的CKG上执行查询并检索到比没有融合的知识图更好的答案。我们还展示了安全分析师可以使用我们的融合CKG来利用的各种推理能力。
After Action Reports (AARs) provide incisive analysis of cyber-incidents. Extracting cyber-knowledge from these sources would provide security analysts with credible information, which they can use to detect or find patterns indicative of a cyber-attack. In this paper, we describe a system to extract information from AARs, aggregate the extracted information by fusing similar entities together, and represent that extracted information in a Cybersecurity Knowledge Graph (CKG). We extract entities by building a customized named entity recognizer called ‘Malware Entity Extractor’ (MEE). We then build a neural network to predict how pairs of ‘malware entities’ are related to each other. When we have predicted entity pairs and the relationship between them, we assert the ‘entity-relationship set’ in a CKG. Our next step in the process is to fuse similar entities, to improve our CKG. This fusion helps represent intelligence extracted from multiple documents and reports. The fused CKG has knowledge from multiple AARs, with relationships between entities extracted from separate reports. As a result of this fusion, a security analyst can execute queries and retrieve better answers on the fused CKG, than a knowledge graph with no fusion. We also showcase various reasoning capabilities that can be leveraged by a security analyst using our fused CKG.