activity
20182021
most citedA System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence

1 citations · 1 across the 1 of their papers we have counts for

collaborators

7 papers

cs.CR20211 cited

A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence

Peng Gao, Fei Shao, Xiaoyuan Liu +7

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated cyber attacks. However, existing approaches require non-trivial efforts of manual query…

cs.CR2020

Enabling Efficient Cyber Threat Hunting With Cyber Threat Intelligence

Peng Gao, Fei Shao, Xiaoyuan Liu +6

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated attacks. However, existing approaches require non-trivial efforts of manual query const…

cs.CR2019

Querying Streaming System Monitoring Data for Enterprise System Anomaly Detection

Peng Gao, Xusheng Xiao, Ding Li +4

The need for countering Advanced Persistent Threat (APT) attacks has led to the solutions that ubiquitously monitor system activities in each enterprise host, and perform timely ab…

cs.CR2018

A Query System for Efficiently Investigating Complex Attack Behaviors for Enterprise Security

Peng Gao, Xusheng Xiao, Zhichun Li +4

The need for countering Advanced Persistent Threat (APT) attacks has led to the solutions that ubiquitously monitor system activities in each enterprise host, and perform timely at…

cs.CR2018

SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior Detection

Peng Gao, Xusheng Xiao, Ding Li +6

Recently, advanced cyber attacks, which consist of a sequence of steps that involve many vulnerabilities and hosts, compromise the security of many well-protected businesses. This…

cs.CR2018

AIQL: Enabling Efficient Attack Investigation from System Monitoring Data

Peng Gao, Xusheng Xiao, Zhichun Li +4

The need for countering Advanced Persistent Threat (APT) attacks has led to the solutions that ubiquitously monitor system activities in each host, and perform timely attack invest…