AttRSeq: Attack story reconstruction via sequence mining on causal graph

Fangtao Zhang, Rujie Dai, Xiu Ma · 2023

With massive alerts to investigate, cyber analysts often face with alert fatigue and may miss true attack events. As cyber-attacks are becoming increasingly targeted and sophisticated, many attack story reconstruction techniques are proposed to trace back attack steps based on causal graphs and help cyber analysts understand how an attack unfolds. However, most existing techniques are heuristic or rule-based and require a great deal of effort to develop the rules or heuristics. This paper presents AttRSeq, a framework discovering similar attack steps across different APT instances and identifying nodes that contribute to an attack. Regarding attack entities in causal graphs, AttRSeq extracts a set of attack sequences recording critical steps of an APT attack. It then leverages an attention-based Bi-directional Long Short-Term Memory (Bi-LSTM) to learn key sequential patterns of attack and non-attack behaviors to detect ones that contribute to an attack. To verify the effectiveness of our proposed method, we conduct comparison experiments on a public dataset. The results show that our proposed model has a robust performance that exceeds the current state of the art.

Read the paper · More papers on PaperTik