NLP-based Entity Behavior Analytics for Malware Detection
Pejman Najafi, Daniel Köhler, Feng Cheng, Christoph Meinel · 2021
In this research, we formulate malware detection as a large-scale data-mining problem within Security Information and Event Management (SIEM) systems. We hypothesize that behavioral analysis of executable/process activities, such as file reads/writes, process creations, network connections, or registry modifications, enables the detection of advanced stealthy malware. To achieve this detection, we model processes behaviors as a set of directed acyclic graph streams and identify outliers in the set of graph streams. We enable this detection by conversion of the behavioral graph streams into documents, embedding using state-of-the-art Natural Language Processing model, and eventually performing novel outlier detection on the high dimensional vector representation of the documents. We evaluate our approach in a real-world setting, next to the SIEM system of a large-scale international enterprise (over 3TB of EDR logs). The proposed method has shown the capability to detect previously unknown threats.