FUDD: Threat Hunting Framework Utilizing Graph-Based Anomaly Detection on Log Data

Robin Buchta, Kilian Dangendorf, Carsten Kleiner, Felix Heine, Gabi Dreo Rodosek · 2025

Our communication systems face a constant threat of cyberattacks. Advanced attacks go beyond the capabili-ties of established detection methods. Threat Hunting (TH), a hypothesis-driven, analyst-centric approach, is one technique for detecting advanced persistent threat (APT) activities. However, it can be resource-intensive, require specialized expertise, and may not always produce immediate or clear results. In addition to TH, anomaly detection is also a way to detect APT activities, but it suffers from a high false positive rate (FPR). We explore combining TH with anomaly detection to address the high FPR in anomaly detection, reduce the analyst's workload, and improve hunting success. Our approach, FUDD, a TH framework that applies graph-based anomaly detection on log data to detect APT activities, provides the threat hunter with an anomaly report based on a hypothesis. The anomaly report makes unusual behavior visible, potentially validating the initial hypothesis and facilitating the evolution and generation of more specific hypothe-ses. Our evaluation involves instantiating FUDD and applying it to two DARPA Transparent Computing sample datasets. Our results show that analysts can use the report's top$k$anomalies to identify attacks based on an initially very broad hypothesis. Besides attacks, the report also highlights other unusual system behavior. . which helps enhance the system's overall security.

Read the paper · More papers on PaperTik