L/STIM: A Framework for Detecting Multi-Stage Cyber Attacks
Igor Zelichenok, Igor Vitalievich Kotenko · 2024
The number of cyber-attacks is growing every year, and the attacks themselves are becoming more complex. Multi-step attacks are a separate category. Their peculiarity is that they are performed in several stages, are often aimed at many nodes and affect many devices. Thanks to deep learning models, it became possible to automatically deliver the context of events from chains of records about the state of the system. Neural networks show high efficiency in the process of establishing relationships when analyzing data with a large number of features. The paper presents the L/STIM framework, which is designed to identify multi-step attacks using a combination of big data processing methods and machine learning. Thanks to short-term and long-term analysis, L/STIM is able to detect multi-step attacks with a long execution period with an accuracy of up to 98% on a binary classifier and up to 82% on a multi-class classifier.