5 papers
Towards Small Language Models for Security Query Generation in SOC Workflows
Saleha Muzammil, Rahul Reddy, Vishal Kamalakrishnan +2
Analysts in Security Operations Centers routinely query massive telemetry streams using Kusto Query Language (KQL). Writing correct KQL requires specialized expertise, and this dep…
Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System
Rui Zhao, Muhammad Shoaib, Viet Tung Hoang +1
Existing tamper-evident logging systems suffer from high overhead and severe data loss in high-load settings, yet only provide coarse-grained tamper detection. Moreover, installing…
Are We There Yet? Unraveling the State-of-the-Art Graph Network Intrusion Detection Systems
Chenglong Wang, Pujia Zheng, Jiaping Gui +2
Network Intrusion Detection Systems (NIDS) are vital for ensuring enterprise security. Recently, Graph-based NIDS (GIDS) have attracted considerable attention because of their capa…
HADES: Detecting Active Directory Attacks via Whole Network Provenance Analytics
Qi Liu, Kaibin Bao, Wajih Ul Hassan +1
Due to its crucial role in identity and access management in modern enterprise networks, Active Directory (AD) is a top target of Advanced Persistence Threat (APT) actors. Conventi…
Accurate and Scalable Detection and Investigation of Cyber Persistence Threats
Qi Liu, Muhammad Shoaib, Mati Ur Rehman +3
In Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to…