3 citations · 6 across the 4 of their papers we have counts for
8 papers
ActMiner: Applying Causality Tracking and Increment Aligning for Graph-based Cyber Threat Hunting
Mingjun Ma, Tiantian Zhu, Shuang Li +4
To defend against Advanced Persistent Threats on the endpoint, threat hunting employs security knowledge such as cyber threat intelligence to continuously analyze system audit logs…
METANOIA: A Lifelong Intrusion Detection and Investigation System for Mitigating Concept Drift
Jie Ying, Mengce Zheng, Jungan Chen +3
As Advanced Persistent Threat (APT) complexity increases, provenance data is increasingly used for detection. Anomaly-based systems are gaining attention due to their attack-knowle…
DEHYDRATOR: Enhancing Provenance Graph Storage via Hierarchical Encoding and Sequence Generation
Jie Ying, Tiantian Zhu, Mingqi Lv +1
As the scope and impact of cyber threats have expanded, analysts utilize audit logs to hunt threats and investigate attacks. The provenance graphs constructed from kernel logs are…
MultiKG: Multi-Source Threat Intelligence Aggregation for High-Quality Knowledge Graph Representation of Attack Techniques
Jian Wang, Tiantian Zhu, Chunlin Xiong +1
The construction of attack technique knowledge graphs aims to transform various types of attack knowledge into structured representations for more effective attack procedure modeli…
CRUcialG: Reconstruct Integrated Attack Scenario Graphs by Cyber Threat Intelligence Reports
Wenrui Cheng, Tiantian Zhu, Tieming Chen +7
Cyber Threat Intelligence (CTI) reports are factual records compiled by security analysts through their observations of threat events or their own practical experience with attacks…
Nip in the Bud: Forecasting and Interpreting Post-exploitation Attacks in Real-time through Cyber Threat Intelligence Reports
Tiantian Zhu, Jie Ying, Tieming Chen +6
Advanced Persistent Threat (APT) attacks have caused significant damage worldwide. Various Endpoint Detection and Response (EDR) systems are deployed by enterprises to fight agains…