activity
20242026
collaborators
Showing cs.CRShow all

8 papers · 1 filter

cs.CR2026

ProHunter: A Comprehensive APT Hunting System Based on Whole-System Provenance

Xuebo Qiu, Mingqi Lv, Yimei Zhang +2

Advanced Persistent Threats (APTs) remain difficult to detect due to their stealthy nature and long-term persistence. To tackle this challenge, provenance-based threat hunting has…

cs.CR2026

METANOIA: A Lifelong Intrusion Detection and Investigation System for Mitigating Concept Drift

Jie Ying, Mengce Zheng, Jungan Chen +3

As Advanced Persistent Threat (APT) complexity increases, provenance data is increasingly used for detection. Anomaly-based systems are gaining attention due to their attack-knowle…

cs.CR2025

ActMiner: Applying Causality Tracking and Increment Aligning for Graph-based Cyber Threat Hunting

Mingjun Ma, Tiantian Zhu, Shuang Li +4

To defend against Advanced Persistent Threats on the endpoint, threat hunting employs security knowledge such as cyber threat intelligence to continuously analyze system audit logs…

cs.CR2024

DEHYDRATOR: Enhancing Provenance Graph Storage via Hierarchical Encoding and Sequence Generation

Jie Ying, Tiantian Zhu, Mingqi Lv +1

As the scope and impact of cyber threats have expanded, analysts utilize audit logs to hunt threats and investigate attacks. The provenance graphs constructed from kernel logs are…

cs.CR2024

CRUcialG: Reconstruct Integrated Attack Scenario Graphs by Cyber Threat Intelligence Reports

Wenrui Cheng, Tiantian Zhu, Tieming Chen +7

Cyber Threat Intelligence (CTI) reports are factual records compiled by security analysts through their observations of threat events or their own practical experience with attacks…

cs.CR2024

TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning

Mingqi Lv, HongZhe Gao, Xuebo Qiu +4

APT (Advanced Persistent Threat) with the characteristics of persistence, stealth, and diversity is one of the greatest threats against cyber-infrastructure. As a countermeasure, e…