UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
复制标题

DOI:
10.14722/ndss.2020.24046
复制
发表时间:
2020-01
期刊:
ArXiv
影响因子:
--
通讯作者:
Xueyuan Han;Thomas Pasquier;Adam Bates;James W. Mickens;M. Seltzer
Xueyuan Han;Thomas Pasquier;Adam Bates;James W. Mickens;M. Seltzer
中科院分区:
其他
文献类型:
--
作者:
Xueyuan Han;Thomas Pasquier;Adam Bates;James W. Mickens;M. Seltzer

文献摘要

被引文献

相似文献

高级持续性威胁(apt)由于其“低而慢”的攻击模式和频繁使用零日漏洞而难以检测。我们介绍了UNICORN,这是一种基于异常的APT检测器,可以有效地利用数据来源分析。从建模到检测,UNICORN专门为apt的独特特性量身定制设计。通过广泛而高效的图形分析,UNICORN探索了提供丰富上下文和历史信息的来源图形,以识别没有预定义攻击签名的隐形异常活动。它使用图形草图技术,总结了长时间运行的系统执行,具有空间效率,以对抗长时间内发生的缓慢攻击。UNICORN使用一种新颖的建模方法进一步提高了其检测能力,以了解系统演变过程中的长期行为。我们的评估表明,UNICORN优于现有的最先进的APT检测系统,并能高精度地检测出现实生活中的APT场景。
Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based APT detector that effectively leverages data provenance analysis. From modeling to detection, UNICORN tailors its design specifically for the unique characteristics of APTs. Through extensive yet time-efficient graph analysis, UNICORN explores provenance graphs that provide rich contextual and historical information to identify stealthy anomalous activities without pre-defined attack signatures. Using a graph sketching technique, it summarizes long-running system execution with space efficiency to combat slow-acting attacks that take place over a long time span. UNICORN further improves its detection capability using a novel modeling approach to understand long-term behavior as the system evolves. Our evaluation shows that UNICORN outperforms an existing state-of-the-art APT detection system and detects real-life APT scenarios with high accuracy.