Showing cs.CRShow all
3 papers · 1 filter
cs.CR2025
ActMiner: Applying Causality Tracking and Increment Aligning for Graph-based Cyber Threat Hunting
Mingjun Ma, Tiantian Zhu, Shuang Li +4
To defend against Advanced Persistent Threats on the endpoint, threat hunting employs security knowledge such as cyber threat intelligence to continuously analyze system audit logs…
cs.CR2025
OMNISEC: LLM-Driven Provenance-based Intrusion Detection via Retrieval-Augmented Behavior Prompting
Wenrui Cheng, Tiantian Zhu, Shunan Jing +4
Recently, Provenance-based Intrusion Detection Systems (PIDSes) have been widely used for endpoint threat analysis. These studies can be broadly categorized into rule-based detecti…
cs.CR2024
SPARSE: Semantic Tracking and Path Analysis for Attack Investigation in Real-time
Jie Ying, Tiantian Zhu, Wenrui Cheng +6
As the complexity and destructiveness of Advanced Persistent Threat (APT) increase, there is a growing tendency to identify a series of actions undertaken to achieve the attacker's…