Representation-enhanced APT Detection Using Contrastive Learning

Fengxi Zhou, Baoming Chang, Wen Yu, Dan Meng · 2023

Advanced Persistent Threats (APTs) are low-and-slow attack patterns and difficult to detect due to their strong concealment. Recently, provenance-based method demonstrates promising prospect in APT detection. However, existing approaches suffer from following several limitations. First, rule-based models heavily rely on domain-specific knowledges and sophisticated matching mechanism from rules to system logs. Second, current anomaly-based techniques require attack-free data to train model and hard to acquire fine-grained detection results to locate attack events. An important reason for undermining the detection capacity of model is the notorious dependency explosion problem and data imbalance problem. Both of problems make the vector representations of benign events and attack events similar, therefore, the model can not differentiate them well. In this paper, we propose DeepDist, which can enhance the entity vector representation by contrastive learning. In this way, we force the projection of benign and attack entities into different feature regions to improve the detection ability of the model. Then we correlate these detected entities to constitute attack events. During our evaluation against thirteen real APT attack scenarios of two datasets, DeepDist shows the detection results with high accuracy.

Read the paper · More papers on PaperTik