NetHawk : Hunting Advanced Persistent Threats via Structural and Temporal Graph Anomalies

Benjamin Bowman, Isaiah J. King, Rimon Melamed, H. Howie Huang · 2024

Traditional signature-based perimeter defenses are not sufficient for defending enterprise computer networks against modern-day cyber threats. Advanced Persistent Threats can easily evade known techniques and signatures. Behavioral analytics have been proposed as a way to move beyond signatures to detect stealthy and sophisticated threat actors better. However, current implementations of these analytics are either too granular to generate meaningful alerts, or too strict, relying on user-generated patterns to explicitly describe malicious behaviors. In this work, we introduce a new system, NetHawk, which represents cyber activity within an enterprise network as an attributed graph. It then uses this graph to conduct behavioral anomaly detection to identify structural and temporal graph anomalies. We further leverage the graph structure to generate high-fidelity and complete incident reports on malicious activity based on connected-component analysis. We apply our techniques to two open-source datasets: the DARPA OpTC dataset, and the LANL Comprehensive Multi-Source Cyber Security Events dataset. We detect malicious activity with high accuracy while maintaining minimal CPU and memory utilization. We also demonstrate that our approach generates meaningful, easy-to-understand alerts that align with the human descriptions of the attacks we analyze.

Read the paper · More papers on PaperTik