DEPCOMM: Graph Summarization on System Audit Logs for Attack Investigation

DEPCOMM: Graph Summarization on System Audit Logs for Attack Investigation
复制标题

DOI:
10.1109/sp46214.2022.9833632
复制
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Zhiqiang Xu;Pengcheng Fang;Changlin Liu;Xusheng Xiao;Yu Wen;Dan Meng
Zhiqiang Xu;Pengcheng Fang;Changlin Liu;Xusheng Xiao;Yu Wen;Dan Meng
中科院分区:
其他
文献类型:
--
作者:
Zhiqiang Xu;Pengcheng Fang;Changlin Liu;Xusheng Xiao;Yu Wen;Dan Meng

文献摘要

被引文献

相似文献

因果关系分析从系统审核日志中生成一个依赖图,这是攻击研究的重要解决方案,在依赖图中,节点代表系统实体(例如,过程和文件),而边缘则代表实体之间的依赖关系,代表了在文件中的依赖(例如,偶然的结果)。大型攻击投资,我们提出了攻击投资的挑战,我们提出了一种图形摘要方法,从依赖图中生成摘要图,通过将大图分配到以过程为中心的社区中,并为每个社区提供了互补的摘要,每个社区都组成了一组彼此共同协调某些系统活动(E.G.G.G.G.,和E.G.,以及E.G.,以及E.G.,以及E.G.,以及E.G.,以及。这些过程在社区中访问,Depcomm进一步确定了由不太重要的重复系统活动引起的,并在这些边缘上执行压缩,Depcomm使用代表跨社区的信息来捕获一组攻击的过程在真实的攻击中($ \ sim 150 $ $ $ \ sim \ sim $ \ sim \ sim 70 \ times $ bed以比92.1的平均成绩,与这些$ 32.1相比,$ \ sime $ comm $ comms $ shie $ commm $ shie a $ commm $ sage comm of shie $ comms $ 2.在检测社区。通过与Holmes合作,Depcomm可以通过召回96.2%的案例研究来识别与攻击相关的社区。
Causality analysis generates a dependency graph from system audit logs, which has emerged as an important solution for attack investigation. In the dependency graph, nodes represent system entities (e.g., processes and files) and edges represent dependencies among entities (e.g., a process writing to a file). Despite the promising early results, causality analysis often produces a large graph (> 100,000 edges) and it is a daunting task for security analysts to inspect such a large graph for attack investigation. To address challenges in attack investigation, we propose DEPCOMM, a graph summarization approach that generates a summary graph from a dependency graph by partitioning a large graph into process-centric communities and presenting summaries for each community. Specifically, each community consists of a set of intimate processes that cooperate with each other to accomplish certain system activities (e.g., file compression), and the resources (e.g., files) accessed by these processes. Within a community, DEPCOMM further identifies redundant edges caused by less-important and repetitive system activities, and perform compression on these edges. Finally, DEPCOMM generates the summary for each community using the InfoPaths that represent the information flows across communities. These InfoPaths are more likely to capture a set of attack-related processes that work together to achieve certain malicious goals. Our evaluations on real attacks ($\sim 150$ million events) demonstrate that DEPCOMM generates 18.4 communities on average for a dependency graph, which is $\sim 70 \times$ smaller than the original graph. Our compression further reduces the edges in each community to 32.1 on average. Compared with the 9 state-of-the-art community detection algorithms, on average, DEPCOMM achieves a $2.29\times$ better F1-score than these algorithms in detecting communities. Through cooperating with the automatic techniques HOLMES, DEPCOMM can identify attack-related communities by a recall of 96.2%. Our case studies on the real attacks also demonstrate DEPCOMM’s effectiveness in facilitating attack investigation.