English

A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence

Cryptography and Security 2021-02-26 v2 Computation and Language Databases

Abstract

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated cyber attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the rich external knowledge about threat behaviors provided by open-source Cyber Threat Intelligence (OSCTI). To bridge the gap, we build ThreatRaptor, a system that facilitates cyber threat hunting in computer systems using OSCTI. Built upon mature system auditing frameworks, ThreatRaptor provides (1) an unsupervised, light-weight, and accurate NLP pipeline that extracts structured threat behaviors from unstructured OSCTI text, (2) a concise and expressive domain-specific query language, TBQL, to hunt for malicious system activities, (3) a query synthesis mechanism that automatically synthesizes a TBQL query from the extracted threat behaviors, and (4) an efficient query execution engine to search the big system audit logging data.

Keywords

Cite

@article{arxiv.2101.06761,
  title  = {A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence},
  author = {Peng Gao and Fei Shao and Xiaoyuan Liu and Xusheng Xiao and Haoyuan Liu and Zheng Qin and Fengyuan Xu and Prateek Mittal and Sanjeev R. Kulkarni and Dawn Song},
  journal= {arXiv preprint arXiv:2101.06761},
  year   = {2021}
}

Comments

Accepted paper at ICDE 2021 demonstrations track. arXiv admin note: substantial text overlap with arXiv:2010.13637

R2 v1 2026-06-23T22:14:57.648Z