用推荐模型挖掘潜在攻击技术关联,辅助安全分析师发现隐藏威胁
Technique Inference Engine: A Recommender Model to Support Cyber Threat Hunting
- 基于威胁情报报告构建最大规模TTP标注数据集
- 通过隐式反馈模型预测攻击中可能共现的技术组合
- 适合网络安全分析师和威胁狩猎团队使用
网络威胁狩猎是主动搜索网络中潜在威胁的行为。由于网络流量庞大、攻击技术多样且持续演化,威胁狩猎面临巨大挑战。为此,我们提出技术推断引擎(Technique Inference Engine),用于推断与已观测攻击行为相关的战术、技术和程序(TTPs)。我们构建了目前(据我们所知)规模最大、经TTP标注的威胁情报(CTI)报告数据集。考虑到技术常被低估报告,我们应用多种隐式反馈推荐模型,从数据中预测某次攻击行动中可能涉及但未明确提及的技术。我们结合网络安全分析师的实际需求评估结果,并使用t-SNE可视化模型嵌入。代码与网页界面均已开源。
原文摘要 · Abstract (English)
Cyber threat hunting is the practice of proactively searching for latent threats in a network. Engaging in threat hunting can be difficult due to the volume of network traffic, variety of adversary techniques, and constantly evolving vulnerabilities. To aid analysts in identifying techniques which may be co-occurring as part of a campaign, we present the Technique Inference Engine, a tool to infer tactics, techniques, and procedures (TTPs) which may be related to existing observations of adversarial behavior. We compile the largest (to our knowledge) available dataset of cyber threat intelligence (CTI) reports labeled with relevant TTPs. With the knowledge that techniques are chronically under-reported in CTI, we apply several implicit feedback recommender models to the data in order to predict additional techniques which may be part of a given campaign. We evaluate the results in the context of the cyber analyst's use case and apply t-SNE to visualize the model embeddings. We provide our code and a web interface.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。