English
Related papers

Related papers: Provenance-based Intrusion Detection: Opportunitie…

200 papers

Advanced Persistent Threats (APTs) remain difficult to detect due to their stealthy nature and long-term persistence. To tackle this challenge, provenance-based threat hunting has gained traction as a proactive defense mechanism. This…

Cryptography and Security · Computer Science 2026-03-23 Xuebo Qiu , Mingqi Lv , Yimei Zhang , Tiantian Zhu , Tieming Chen

Provenance analysis based on system audit data has emerged as a fundamental approach for investigating Advanced Persistent Threat (APT) attacks. Due to the high concealment and long-term persistence of APT attacks, they are only represented…

Cryptography and Security · Computer Science 2025-10-28 Qi Sheng

Data provenance analysis has been used as an assistive measure for ensuring system integrity. However, such techniques are typically reactive approaches to identify the root cause of an attack in its aftermath. This is in part due to fact…

Cryptography and Security · Computer Science 2021-06-02 Shamaria Engram , Tyler Kaczmarek , Alice Lee , David Bigelow

Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based APT detector that effectively leverages data provenance…

Cryptography and Security · Computer Science 2020-01-15 Xueyuan Han , Thomas Pasquier , Adam Bates , James Mickens , Margo Seltzer

Provenance graph analysis plays a vital role in intrusion detection, particularly against Advanced Persistent Threats (APTs), by exposing complex attack patterns. While recent systems combine graph neural networks (GNNs) with natural…

Cryptography and Security · Computer Science 2026-04-21 Yi Huang , Shaofei Li , Yao Guo , Xiangqun Chen , Ding Li , Wajih Ul Hassan

Provenance is an increasing concern due to the ongoing revolution in sharing and processing scientific data on the Web and in other computer systems. It is proposed that many computer systems will need to become provenance-aware in order to…

Programming Languages · Computer Science 2014-01-06 Umut A. Acar , Amal Ahmed , James Cheney , Roly Perera

Cyber supply chain, encompassing digital asserts, software, hardware, has become an essential component of modern Information and Communications Technology (ICT) provisioning. However, the growing inter-dependencies have introduced numerous…

Cryptography and Security · Computer Science 2025-04-04 Zhuoran Tan , Christos Anagnostopoulos , Jeremy Singer

System level provenance is of widespread interest for applications such as security enforcement and information protection. However, testing the correctness or completeness of provenance capture tools is challenging and currently done…

Cryptography and Security · Computer Science 2019-09-26 Sheung Chi Chan , James Cheney , Pramod Bhatotia , Thomas Pasquier , Ashish Gehani , Hassaan Irshad , Lucian Carata , Margo Seltzer

Security research has concentrated on converting operating system audit logs into suitable graphs, such as provenance graphs, for analysis. However, provenance graphs can grow very large requiring significant computational resources beyond…

Intrusion detection systems (IDS) help detect unauthorized activities or intrusions that may compromise the confidentiality, integrity or availability of a resource. This paper presents a general overview of IDSs, the way they are…

Cryptography and Security · Computer Science 2017-12-04 Liu Hua Yeo , Xiangdong Che , Shalini Lakkaraju

With the growing digitalization all over the globe, the relevance of network security becomes increasingly important. Machine learning-based intrusion detection constitutes a promising approach for improving security, but it bears several…

Machine Learning · Computer Science 2025-08-19 Aleksei Liuliakov , Alexander Schulz , Luca Hermes , Barbara Hammer

Intrusion Detection and/or Prevention Systems (IDPS) represent an important line of defence against a variety of attacks that can compromise the security and proper functioning of an enterprise information system. Along with the widespread…

Cryptography and Security · Computer Science 2013-04-19 Shalvi Dave , Bhushan Trivedi , Jimit Mahadevia

Today by growing network systems, security is a key feature of each network infrastructure. Network Intrusion Detection Systems (IDS) provide defense model for all security threats which are harmful to any network. The IDS could detect and…

Software Engineering · Computer Science 2014-03-06 Mehdi Bahrami , Mohammad Bahrami

Risk assessment plays a crucial role in ensuring the security and resilience of modern computer systems. Existing methods for conducting risk assessments often suffer from tedious and time-consuming processes, making it challenging to…

Cryptography and Security · Computer Science 2023-07-27 Simon Unger , Ektor Arzoglou , Markus Heinrich , Dirk Scheuermann , Stefan Katzenbeisser

Provenance graph-based intrusion detection systems are deployed on hosts to defend against increasingly severe Advanced Persistent Threat. Using Graph Neural Networks to detect these threats has become a research focus and has demonstrated…

Cryptography and Security · Computer Science 2025-08-11 Weiheng Wu , Wei Qiao , Teng Li , Yebo Feng , Zhuo Ma , Jianfeng Ma , Yang Liu

Endpoint Detection and Response (EDR) solutions embrace the method of attack provenance graph to discover unknown threats through system event correlation. However, this method still faces some unsolved problems in the fields of…

Cryptography and Security · Computer Science 2026-02-18 Peilun Wu , Nan Sun , Nour Moustafa , Youyang Qu , Ming Ding

The immune system provides an ideal metaphor for anomaly detection in general and computer security in particular. Based on this idea, artificial immune systems have been used for a number of years for intrusion detection, unfortunately so…

Neural and Evolutionary Computing · Computer Science 2010-07-05 Uwe Aickelin , Julie Greensmith

We present ANUBIS, a highly effective machine learning-based APT detection system. Our design philosophy for ANUBIS involves two principal components. Firstly, we intend ANUBIS to be effectively utilized by cyber-response teams. Therefore,…

Cryptography and Security · Computer Science 2021-12-22 Md. Monowar Anjum , Shahrear Iqbal , Benoit Hamelin

A novel approach to analyze statistically the network traffic raw data is proposed. The huge amount of raw data of actual network traffic from the Intrusion Detection System is analyzed to determine if a traffic is a normal or harmful one.…

Cryptography and Security · Computer Science 2014-05-29 A. A. Waskita , H. Suhartanto , P. D. Persadha , L. T. Handoko

Backdoor attack is a powerful attack algorithm to deep learning model. Recently, GNN's vulnerability to backdoor attack has been proved especially on graph classification task. In this paper, we propose the first backdoor detection and…

Artificial Intelligence · Computer Science 2022-09-08 Bingchen Jiang , Zhao Li