HOUND: Log Analysis Support for Threat Hunting by Log Visualization

Rei Yamagishi, Takahiro Katayama, Nobutaka Kawaguchi, Tomohiro Shigemoto · 2022 12th International Congress on Advanced Applied Informatics (IIAI-AAI) · 2022

Threat hunting is a methodology to discover threats that have already penetrated organizations without relying on existing security devices. Threat hunting has been attracting attention because the traditional cyberattack process cannot catch advanced threats. In threat hunting, an operator analyzes multiple types of logs and collects traces of attacks in terms of tactics, techniques, and procedures (TTP). While existing log visualization technology can understand the log overview and discover suspicious points, it does not upport detailed analysis in a tabular format. Therefore, analysts must read each log entry carefully during a detailed analysis. In this paper, we propose a detailed analysis support system for threat hunting using three key ideas: (i) making TTP icons to help translate events, (ii) similarity value visualization, and (iii) relevance visualization between log entries to help an operator decide which entries should be analyzed next. We propose a " Hunting Operation Utilities for Need Decision " (HOUND) system that implements the three key ideas.

Read the paper · More papers on PaperTik