arXiv:2505.03817cs.CRcs.AI2025-05被引 2

用逆强化学习从日志中挖掘黑客行为偏好,提升威胁溯源能力

Modeling Behavioral Preferences of Cyber Adversaries Using Inverse Reinforcement Learning

  • 基于审计日志构建攻击路径,用逆强化学习推断黑客行为偏好
  • 实验证明低层日志可自动揭示黑客主观偏好,且偏好具稳定性
  • 适合安全分析、威胁情报与攻击者画像研究者使用

本文提出一种基于逆强化学习(IRL)的攻击者行为偏好建模方法,利用系统级审计日志对攻击者进行整体建模。传统方法依赖不断更新的攻击工具与技术清单追踪威胁主体,但攻击手段虽变化频繁,行为偏好却相对稳定。本方法将攻击者视为在主机环境中具有未知偏好的决策专家,通过攻击溯源图从审计日志中提取状态-动作轨迹,并在真实攻击数据集上验证。结果首次证明,低层取证数据可自动揭示攻击者的主观偏好,这些偏好在不同工具下保持不变,反映攻击者内在特质。因此,推断出的偏好可作为独特的行为指纹,辅助威胁归属判定。

原文摘要 · Abstract (English)

This paper presents a holistic approach to attacker preference modeling from system-level audit logs using inverse reinforcement learning (IRL). Adversary modeling is an important capability in cybersecurity that lets defenders characterize behaviors of potential attackers, which enables attribution to known cyber adversary groups. Existing approaches rely on documenting an ever-evolving set of attacker tools and techniques to track known threat actors. Although attacks evolve constantly, attacker behavioral preferences are intrinsic and less volatile. Our approach learns the behavioral preferences of cyber adversaries from forensics data on their tools and techniques. We model the attacker as an expert decision-making agent with unknown behavioral preferences situated in a computer host. We leverage attack provenance graphs of audit logs to derive a state-action trajectory of the attack. We test our approach on open datasets of audit logs containing real attack data. Our results demonstrate for the first time that low-level forensics data can automatically reveal an adversary's subjective preferences, which serves as an additional dimension to modeling and documenting cyber adversaries. Attackers' preferences tend to be invariant despite their different tools and indicate predispositions that are inherent to the attacker. As such, these inferred preferences can potentially serve as unique behavioral signatures of attackers and improve threat attribution.

逆强化学习威胁建模行为分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。