276 citations · 375 across the 3 of their papers we have counts for
6 papers · 1 filter
OSTINATO: Cross-host Attack Correlation Through Attack Activity Similarity Detection
Sutanu Kumar Ghosh, Kiavash Satvat, Rigel Gjomemo +1
Modern attacks against enterprises often have multiple targets inside the enterprise network. Due to the large size of these networks and increasingly stealthy attacks, attacker ac…
EXTRACTOR: Extracting Attack Behavior from Threat Reports
Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan
The knowledge on attacks contained in Cyber Threat Intelligence (CTI) reports is very important to effectively identify and quickly respond to cyber threats. However, this knowledg…
POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting
Sadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo +1
Cyber threat intelligence (CTI) is being used to search for indicators of attacks that might have compromised an enterprise network for a long time without being discovered. To hav…
ProPatrol: Attack Investigation via Extracted High-Level Tasks
Sadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo +1
Kernel audit logs are an invaluable source of information in the forensic investigation of a cyber-attack. However, the coarse granularity of dependency information in audit logs l…
HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows
Sadegh M. Milajerdi, Rigel Gjomemo, Birhanu Eshete +2
In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of…
SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data
Md Nahid Hossain, Sadegh M Milajerdi, Junao Wang +5
We present an approach and system for real-time reconstruction of attack scenarios on an enterprise host. To meet the scalability and real-time needs of the problem, we develop a p…