FORTRESS: Shortest Feature Weighted Path System for Attack Investigation

Qianlong Xiao, Rongrong Chen, Minghao Hu, Jiaxu Xing, Fei Tang, Lejun Zhang, Jing Qiu · 2023

The use of provenance graphs for network attack investigation is common, but large audit data logs pose challenges for security analysts. To address this, we propose FORTRESS, a system that computes feature weights for edges and nodes to conduct attack investigations. We assign weight features to graph edges and nodes to represent their importance. These weight features are converted from those attributes that are highly related to the attack behavior through algorithmic computation. By retracing the shortest path starting from the Point of Interest (POI) event and organizing the paths based on their lengths, we ascertain the point of entry for the attack. Forward analysis based on distance thresholds generates the attack investigation graph. FORTRESS significantly reduces provenance graph size, improves investigation accuracy through node and edge feature fusion, and enhances computational efficiency with edge compression pruning. Evaluating FORTRESS using a real-world dataset and attacks demonstrates its advantages over other techniques in reducing graph size and accurately identifying entry points.

Read the paper · More papers on PaperTik