ProDE: Interpretable APT Detection Method Based on Encoder-decoder Architecture

Fengxi Zhou, Baoming Chang, Yu Wen, Dan Meng · 2023

The detection and analysis of Advanced Persistent Threats (APTs) are pivotal for contemporary network security. Provenance graphs, constructed from audit logs, offer a wealth of contextual information to identify and analyze threats and are popular in APT detection field. However, existing approaches frequently fall short in offering explanatory capabilities for their detection results, placing an additional burden on security analysts. Confronted with coarse-grained detection outcomes, analysts must delve into provenance graphs or audit logs to precisely pinpoint attack entities and events, which can significantly delay the response to threats. In this paper, we propose ProDE, a novel approach that enhances APT detection by providing interpretable results using an encoder-decoder architecture. ProDE initiates the detection process by comparing the encoded representations of the true graph and the predicted graph. Upon detecting abnormalities, the encoder-decoder model is able to decode the encodings into provenance graphs, thereby revealing inconsistencies between the decoded graph and real graph that serve as interpretable results. We evaluate ProDE on two widely used datasets, while taking into account the detection performance, the result shows ProDE can provided the more detailed detection results which provide the interpretation for analysts compared with existing approaches.

Read the paper · More papers on PaperTik