LRBEAL: Learning Representation of Behaviors Extracted from Audit Logs

Jiaxu Xing, Yongxin Cai, Ximing Chen, Chengliang Gao, Yanhao Chen, Jing Qiu · 2024

Audit logs provide data support for intrusion detection and attack investigation. However, these logs are fine-grained, large-scale, and there is a semantic gap between them and user behaviors. This poses challenges for security analysts to identify behaviors and discover abnormal activities. Existing methods abstract user behavior through the information flow between system entities, and perform representation learning and clustering analysis to bridge the semantic gap between logs and behaviors. However, challenges remain in effectively extracting and representing behavior. In this paper, we propose LRBEAL, a framework for behavior analysis based on audit logs. LRBEAL aims to extract behaviors from logs, denoise, represent the behaviors, and identify anomalous behaviors. We design a denoising method specifically for behavior instances, which filters logs by analyzing the correlation between logs and behaviors in order to construct concise and effective behavior instances. Additionally, we propose a behavior representation method based on temporal and semantic analysis, using semi-supervised and contrastive learning to learn semantics in behavior instances under the guidance of the semantics contained in the command lines. Finally, we use DBSCAN to cluster behavior instances and detection anomalous behaviors. We evaluated LRBEAL on DARPA, and the results shows that LRBEAL effectively identifies user behavior and performs well in both behavior identification and anomaly detection.

Read the paper · More papers on PaperTik