论文标题

问题儿童:基于亲子过程关系发现异常模式

ProblemChild: Discovering Anomalous Patterns based on Parent-Child Process Relationships

论文作者

Filar, Bobby, French, David

论文摘要

越来越多的对手攻击不仅仅是独立的可执行文件或脚本。通常,攻击的证据包括传统静态机器学习模型可能会忽略的显着过程遗产。先进的攻击者技术,例如在亲子环境中观察到的“孤立地生活”的“生活在陆地上”变得更加可疑。从亲子过程链中得出的上下文可以帮助识别和分组恶意软件家族,并发现新颖的攻击者技术。对手将这些技术链接起来,以实现持久性,绕过防御和执行动作。传统的基于启发式的检测通常会产生属于构成单一攻击的噪声或不同事件。问题儿童是一个基于图形的框架,旨在解决这些问题。问题儿童应用监督的学习分类器来得出一个加权图,用于将看似截然不同的事件的社区识别为更大的攻击序列。问题儿童应用有条件的概率自动对异常社区进行排名,并抑制通常发生的亲子链。结合使用,分析师可以使用该框架来帮助制作或调整探测器,并随着时间的流逝而减少假阳性。我们评估了问题儿童,以针对APT3攻击的2018 MITER ATT&CK(TM)仿真,以证明其在识别异常的亲子过程链方面的希望。

It is becoming more common that adversary attacks consist of more than a standalone executable or script. Often, evidence of an attack includes conspicuous process heritage that may be ignored by traditional static machine learning models. Advanced attacker techniques, like "living off the land" that appear normal in isolation become more suspicious when observed in a parent-child context. The context derived from parent-child process chains can help identify and group malware families, as well as discover novel attacker techniques. Adversaries chain these techniques to achieve persistence, bypass defenses, and execute actions. Traditional heuristic-based detections often generate noise or disparate events that belong to what constitutes a single attack. ProblemChild is a graph-based framework designed to address these issues. ProblemChild applies a supervised learning classifier to derive a weighted graph used to identify communities of seemingly disparate events into larger attack sequences. ProblemChild applies conditional probability to automatically rank anomalous communities as well as suppress commonly occurring parent-child chains. In combination, this framework can be used by analysts to aid in the crafting or tuning of detectors and reduce false-positives over time. We evaluate ProblemChild against the 2018 MITRE ATT&CK(TM) emulation of APT3 attack to demonstrate its promise in identifying anomalous parent-child process chains.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源