ICITDA 2022 Cover Page

2022

Intrusions have increasingly long kill chains, with various footprints left for detection and investigation, and thus require machine learning to better recognize them.These footprints include threat intelligence in IP's and domains, network sighting in packets, and host sighting in logs and others.Relying on one single data source might result in more false negatives.In this talk, we first argue why AI for cybersecurity and why multiple data sources.Then we introduce a toolchain, CRÈME, we developed to complete the cycle of attack reproduction, multi-dataset collection, machine learning, and F1-score evaluation.With experimental results, we show how and why traffic, log, and statistics combined together could enhance F1 score.The tool serves as a platform for further research.We highlight several important steps towards the MITRE ATT&CK framework where both attack techniques and kill chains (lifecycles) should be recognized.

Read the paper · More papers on PaperTik