Download PDFOpen PDF in browser

PanThreat: Global Resource-Based Anomaly Detection for APTs

EasyChair Preprint 15643

6 pagesDate: January 6, 2025

Abstract

Advanced Persistent Threats (APTs), due to their stealthiness and complexity, have become a significant security challenge for modern enterprises, often causing severe economic losses. To address these threats, researchers have proposed using provenance graphs to model system entities and their dependencies, aiming to capture the complex scenarios of APT attacks. However, existing Provenance-based Intrusion Detection Systems (PIDS) still face the following challenges: (1) Historical interaction information loss due to the truncation of long-term interaction scenarios; (2) The difficulty in capturing long-distance dependencies leads to the loss of crucial contextual information; (3) Existing methods struggle to balance detection efficiency and granularity.

We introduce PanThreat, an online detection system that performs fine-grained, real-time analysis of host system logs to identify malicious activities. PanThreat combines attributes encoding through Word2Vec and position encoding using Laplacian feature matrices, while retaining long-term interaction histories and effectively modeling long-range dependencies within provenance graphs. This integrated approach significantly enhances detection accuracy. Additionally, PanThreat leverages the parallel processing capabilities of Graph Transformers to improve detection efficiency. Evaluations on the DARPA E3 dataset and StreamSpot database demonstrate PanThreat's effectiveness in detecting complex APT attacks, outperforming four state-of-the-art methods while maintaining an average processing speed of 58,140 events per second.

Keyphrases: Host Provenance, Threat Detection, transformer

BibTeX entry
BibTeX does not have the right entry for preprints. This is a hack for producing the correct reference:
@booklet{EasyChair:15643,
  author    = {Wenhao Yan and Weiheng Wu and Bingsheng Bi and Wei Qiao and Bo Jiang and Yuling Liu and Junrong Liu},
  title     = {PanThreat: Global Resource-Based Anomaly Detection for APTs},
  howpublished = {EasyChair Preprint 15643},
  year      = {EasyChair, 2025}}
Download PDFOpen PDF in browser