Malicious Process Identification via System Audit Logs Analysis

Zeri Zhang, Kai Shi, Mengshu Wang, Anxing Jiang · 2023

Constructing a dependency graph through the utilization of system audit logs and subsequently performing causal relationship analysis on this graph has become one of the crucial methods for conducting attack investigations. The introduction of the dependency graph makes it possible to identification malicious system entities by providing correlated information within the context of the attack. In this paper, a method is proposed that combines biased random walks with deep anomaly detection models to identify malicious process entities within dependency graphs. The process begins with the utilization of system audit logs to construct a dependency graph, which is subsequently simplified. In this graph, individual edges are endowed with weights, thus forming a weighted dependency graph. Progressing further, a method of biased random walks is implemented to analyze process entities present within the dependency graph. This analysis effectively captures vital contextual information that represents process behaviors, and subsequently transforming them into embedded vectors. Finally, a deep anomaly detection model is employed to achieve the discovery of attacking processes within the system. The effectiveness of the proposed approach is evaluated on six instances of attacks using the DARPA TC dataset. The experimental results demonstrate the method's proficiency in detecting malicious system entities.

Read the paper · More papers on PaperTik