APTSHIELD: A Stable, Efficient and Real-Time APT Detection System for Linux Hosts

计算机科学 架空(工程) 系统调用 服务拒绝攻击 Rootkit 计算机安全 实时计算 嵌入式系统 操作系统 恶意软件 互联网
作者
Tiantian Zhu,Jinkai Yu,Chunlin Xiong,Wenrui Cheng,Qixuan Yuan,Jie Ying,Tieming Chen,Jiabo Zhang,Mingqi Lv,Yan Chen,Ting Wang,Yuan Fan
出处
期刊:IEEE Transactions on Dependable and Secure Computing [Institute of Electrical and Electronics Engineers]
卷期号:20 (6): 5247-5264 被引量:45
标识
DOI:10.1109/tdsc.2023.3243667
摘要

Advanced Persistent Threat (APT) attacks have caused massive financial loss worldwide. Researchers thereby have proposed a series of solutions to detect APT attacks, such as dynamic/static code analysis, traffic detection, sandbox technology, endpoint detection and response (EDR), etc. However, existing defenses are failed to accurately and effectively defend against the current APT attacks that exhibit strong persistent, stealthy, diverse and dynamic characteristics due to the weak data source integrity, large data processing overhead and poor real-time performance in the process of real-world scenarios. To overcome these difficulties, in this paper we propose APTSHIELD, a stable, efficient and real-time APT detection system for Linux hosts. In the aspect of data collection, audit is selected to stably collect kernel data of the operating system so as to carry out a complete portrait of the attack based on comprehensive analysis and comparison of existing logging tools; In the aspect of data processing, redundant semantics skipping and non-viable node pruning are adopted to reduce the amount of data, so as to reduce the overhead of the detection system; In the aspect of attack detection, an APT attack detection framework based on ATT&CK model is designed to carry out real-time attack response and alarm through the transfer and aggregation of labels. Experimental results on both laboratory and Darpa Engagement show that our system can effectively detect web vulnerability attacks, file-less attacks and remote access trojan attacks, and has a low false positive rate, which adds far more value than the existing frontier work.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
海岛发布了新的文献求助10
刚刚
叶子完成签到,获得积分10
1秒前
小马甲应助阿凡采纳,获得10
1秒前
Stella应助水母绷带采纳,获得10
1秒前
Frank完成签到 ,获得积分10
2秒前
2秒前
bkagyin应助jie采纳,获得10
2秒前
长情琦发布了新的文献求助10
3秒前
4秒前
kaka完成签到,获得积分10
4秒前
yu发布了新的文献求助10
4秒前
4秒前
正直的小熊猫关注了科研通微信公众号
4秒前
深情安青应助TK采纳,获得10
5秒前
不配.应助yanyue采纳,获得100
5秒前
希望天下0贩的0应助GWJ采纳,获得10
5秒前
小二郎应助mookie采纳,获得10
6秒前
小蘑菇应助海岛采纳,获得10
6秒前
斯文败类应助鸡狗不如采纳,获得10
7秒前
烟花应助shilong.yang采纳,获得10
7秒前
7秒前
8秒前
9秒前
9秒前
9秒前
汉堡包应助tangtang采纳,获得10
9秒前
9秒前
10秒前
annis发布了新的文献求助10
10秒前
11秒前
量子星尘发布了新的文献求助10
12秒前
12秒前
充电宝应助Suzzw98采纳,获得10
12秒前
小二郎应助张世瑞采纳,获得10
12秒前
空城琥珀柒关注了科研通微信公众号
12秒前
12秒前
wuqi发布了新的文献求助10
12秒前
陈俊豪完成签到 ,获得积分10
12秒前
fff发布了新的文献求助10
13秒前
balabala给balabala的求助进行了留言
13秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Clinical Microbiology Procedures Handbook, Multi-Volume, 5th Edition 临床微生物学程序手册,多卷,第5版 2000
List of 1,091 Public Pension Profiles by Region 1621
Les Mantodea de Guyane: Insecta, Polyneoptera [The Mantids of French Guiana] | NHBS Field Guides & Natural History 1500
The Victim–Offender Overlap During the Global Pandemic: A Comparative Study Across Western and Non-Western Countries 1000
King Tyrant 720
Sport, Social Media, and Digital Technology: Sociological Approaches 650
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5593599
求助须知:如何正确求助?哪些是违规求助? 4679468
关于积分的说明 14810164
捐赠科研通 4644508
什么是DOI,文献DOI怎么找? 2534573
邀请新用户注册赠送积分活动 1502632
关于科研通互助平台的介绍 1469366