EFSNet: A Threat Detection Method Based on System Event Feature Sequence

Qing Yang, Jiancheng Wang, Jinlong Fei, Qingzhou Yang, Li Ding · 2024

In recent years, provenance graph-based methods have gained widespread usage in system threat detection. However, the sheer volume of data within system logs poses significant challenges for the provenance graph approach. To address this, we introduce Event Feature Sequence Network (EFSNet), a threat detection method that relies on system event feature sequences. EFSNet extracts system features based on diverse event types and quantities, without resorting to intricate graph calculations. Furthermore, we enhance feature extraction by employing a BiGRU-based encoder to capture deeper patterns. We have conducted experiments on public data sets, and the experimental results show that EFSNet has excellent threat detection performance and has certain advantages over existing work.

Read the paper · More papers on PaperTik