Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Accurate and Scalable Detection and Investigation of Cyber Persistence Threats

About

In Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typically manifest in two phases: the "persistence setup" and the subsequent "persistence execution". By causally relating these phases, we enhance our ability to detect persistent threats. First, CPD discerns setups signaling an impending persistent threat and then traces processes linked to remote connections to identify persistence execution activities. A key feature of our system is the introduction of pseudo-dependency edges (pseudo-edges), which effectively connect these disjoint phases using data provenance analysis, and expert-guided edges, which enable faster tracing and reduced log size. These edges empower us to detect persistence threats accurately and efficiently. Moreover, we propose a novel alert triage algorithm that further reduces false positives associated with persistence threats. Evaluations conducted on well-known datasets demonstrate that our system reduces the average false positive rate by 93% compared to state-of-the-art methods.

Qi Liu, Muhammad Shoaib, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, Wajih Ul Hassan• 2024

Related benchmarks

TaskDatasetResultRank
Persistence DetectionDARPA-OpTC
False Positives4
6
Persistence DetectionEP-APT29-1
False Positives (FP)23
6
Persistence DetectionEP-APT29 2
False Positives (FP)14
6
Persistence DetectionEP-Sandworm 1
False Positives8
6
Persistence DetectionDARPA-E5
FP Count7
5
Persistence Attack DetectionATLAS v2
False Positives11
3
Persistence Attack DetectionDARPA OpTC Host 0501
Run Time (min)2
3
Showing 7 of 7 rows

Other info

Follow for update