中文

Threat Trekker:一种网络威胁狩猎方法

密码学与安全 2023-10-09 v1

摘要

威胁狩猎是一种在复杂环境中主动探索、检测和缓解网络攻击的方法论。与常规检测系统不同,威胁狩猎策略假设对手已渗透系统;因此,它们主动搜寻可能表明入侵尝试的任何异常模式或活动。历史上,这一工作通过三种调查方法开展:(1) 假设驱动调查;(2) 失陷指标(IOC);以及 (3) 基于高层机器学习分析的方法。因此,本文引入一种称为 Threat Trekker 的新颖机器学习范式。该方案利用连接器将数据直接输入事件流通道,由算法处理并将反馈回传至其宿主网络。这些实验得出的结论明确确立了采用机器学习对更隐蔽攻击进行分类的有效性。

关键词

引用

@article{arxiv.2310.04197,
  title  = {Threat Trekker: An Approach to Cyber Threat Hunting},
  author = {Ángel Casanova Bienzobas and Alfonso Sánchez-Macián},
  journal= {arXiv preprint arXiv:2310.04197},
  year   = {2023}
}

备注

I am disseminating this outcome to all of you, despite the fact that the results may appear somewhat idealistic, given that certain datasets utilized for the training of the machine learning model comprise simulated data