4 papers
From Context to Rules: Toward Unified Detection Rule Generation
Cheng Meng, Wenxin Le, Xinyi Li +4
Existing methods for detection rule generation are tightly coupled to specific input-output combinations, requiring dedicated pipelines for each. We formalize this problem as a uni…
ProvAgent: Threat Detection Based on Identity-Behavior Binding and Multi-Agent Collaborative Attack Investigation
Wenhao Yan, Ning An, Linxu Li +6
Advanced Persistent Threats (APTs) pose critical challenges to modern cybersecurity due to their multi-stage and stealthy nature. While provenance-based detection approaches show p…
Sentient: Detecting APTs Via Capturing Indirect Dependencies and Behavioral Logic
Wenhao Yan, Ning An, Wei Qiao +5
Advanced Persistent Threats (APTs) are difficult to detect due to their complexity and stealthiness. To mitigate such attacks, many approaches model entities and their relationship…
Winemaking: Extracting Essential Insights for Efficient Threat Detection in Audit Logs
Weiheng Wu, Wei Qiao, Wenhao Yan +5
Advanced Persistent Threats (APTs) are continuously evolving, leveraging their stealthiness and persistence to put increasing pressure on current provenance-based Intrusion Detecti…