KIT | KIT-Bibliothek | Impressum | Datenschutz

Cross-Machine Multi-Phase Advanced Persistent Threat Detection and Investigation via Provenance Analytics

Liu, Qi ORCID iD icon 1
1 Institut für Automation und angewandte Informatik (IAI), Karlsruher Institut für Technologie (KIT)

Abstract:

Attack detection and investigation are an iterative process in practice, in
which security analysts still play an important role as of today. Security
systems for attack detection and investigation need to be designed with
this human-in-the-loop aspect in mind. A practical, reliable attack detection
system is not just a classification system. Rather, it facilitates the investigation
process in unearthing the root causes and attack ramifications, by providing
contextualized and more interpretable detection results. Security analysts
often find it difficult and time consuming to investigate on, associate and
understand the detection results of currently deployed security systems. A
swift and accurate attack detection & investigation process is crucial for
timely and proper attack recovery & remediation.
To support speedy and thorough attack detection & investigation, provenance-based
security systems have been proposed over the past few years. These systems
have proven to be inherently suitable for this critical mission: providing
security analysts with insightful, contextualized, and actionable detection
results for further investigation in a highly automated manner. ... mehr


Volltext §
DOI: 10.5445/IR/1000179480
Veröffentlicht am 28.02.2025
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Automation und angewandte Informatik (IAI)
Publikationstyp Hochschulschrift
Publikationsdatum 28.02.2025
Sprache Englisch
Identifikator KITopen-ID: 1000179480
HGF-Programm 37.12.01 (POF IV, LK 01) Digitalization & System Technology for Flexibility Solutions
Verlag Karlsruher Institut für Technologie (KIT)
Umfang xvii, 198 S.
Art der Arbeit Dissertation
Fakultät Fakultät für Informatik (INFORMATIK)
Institut Institut für Automation und angewandte Informatik (IAI)
Prüfungsdatum 07.02.2025
Schlagwörter Advanced Persistent Threat detection, data provenance analysis, digital forensics, Active Directory, industrial-sector organization security
Nachgewiesen in OpenAlex
Referent/Betreuer Hagenmeyer, Veit
Fischer, Mathias
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page