Resist Dependency Explosion in Attack Investigation With Splittable Tag Propagation and Aggregation

Anyuan Sang, Yuchen Wang, Junbo Jia, Li Yang, Pengbin Feng, Lu Zhou, Jianfeng Ma · IEEE Transactions on Dependable and Secure Computing · 2025

Advanced Persistent Threats (APTs) pose significant security risks to the community. Researchers thereby propose techniques to capture the complex and stealthy scenarios of APT attacks through the use of provenance graphs to model system entities and their dependencies. Particularly, to mitigate the dependency explosion problem in attack investigation using provenance graphs, tag-based and priority-based provenance graphs are frequently utilized for analyzing attacks. These methods use threat tag propagation and threat prioritization to reduce the size of the provenance graph for faster analysis. Unfortunately, these methods can allow more complex and potential attacks to evade detection. To overcome these difficulties, we propose an APT attack investigation system,ProTaging, for APT detection and forensic analysis. By using Tactics, Techniques, and Procedures (TTPs) rules to assign and update the node's threat tag, splittable tag propagation to control the scope of threat information, and threat weight aggregation and prioritized backward analysis during the forensic analysis phase, ProTaging effectively reconstructs attack paths in seconds without dependency explosion. Experimental results on both the simulation dataset, DARPA TC E3, E5 dataset, and DARPA OpTC dataset demonstrate that ProTaging generates smaller dependency graphs (2.5 times smaller) and has fewer false positives (6.7 times fewer) compared to state-of-the-art solutions. Additionally, ProTaging significantly reduces manual investigation effort by approximately 99.9%.

Read the paper · More papers on PaperTik