collaborators

5 papers

cs.CR2026

METANOIA: A Lifelong Intrusion Detection and Investigation System for Mitigating Concept Drift

Jie Ying, Mengce Zheng, Jungan Chen +3

As Advanced Persistent Threat (APT) complexity increases, provenance data is increasingly used for detection. Anomaly-based systems are gaining attention due to their attack-knowle…

cs.CR2024

DEHYDRATOR: Enhancing Provenance Graph Storage via Hierarchical Encoding and Sequence Generation

Jie Ying, Tiantian Zhu, Mingqi Lv +1

As the scope and impact of cyber threats have expanded, analysts utilize audit logs to hunt threats and investigate attacks. The provenance graphs constructed from kernel logs are…

cs.CR2024

CRUcialG: Reconstruct Integrated Attack Scenario Graphs by Cyber Threat Intelligence Reports

Wenrui Cheng, Tiantian Zhu, Tieming Chen +7

Cyber Threat Intelligence (CTI) reports are factual records compiled by security analysts through their observations of threat events or their own practical experience with attacks…

cs.CR2024

Nip in the Bud: Forecasting and Interpreting Post-exploitation Attacks in Real-time through Cyber Threat Intelligence Reports

Tiantian Zhu, Jie Ying, Tieming Chen +6

Advanced Persistent Threat (APT) attacks have caused significant damage worldwide. Various Endpoint Detection and Response (EDR) systems are deployed by enterprises to fight agains…

cs.CR2024

SPARSE: Semantic Tracking and Path Analysis for Attack Investigation in Real-time

Jie Ying, Tiantian Zhu, Wenrui Cheng +6

As the complexity and destructiveness of Advanced Persistent Threat (APT) increase, there is a growing tendency to identify a series of actions undertaken to achieve the attacker's…