activity
20182023
most citedPOIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting

276 citations · 375 across the 3 of their papers we have counts for

collaborators
Showing cs.CRShow all

6 papers · 1 filter

cs.CR2023

OSTINATO: Cross-host Attack Correlation Through Attack Activity Similarity Detection

Sutanu Kumar Ghosh, Kiavash Satvat, Rigel Gjomemo +1

Modern attacks against enterprises often have multiple targets inside the enterprise network. Due to the large size of these networks and increasingly stealthy attacks, attacker ac…

cs.CR20217 cited

EXTRACTOR: Extracting Attack Behavior from Threat Reports

Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan

The knowledge on attacks contained in Cyber Threat Intelligence (CTI) reports is very important to effectively identify and quickly respond to cyber threats. However, this knowledg…

cs.CR2019276 cited

POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting

Sadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo +1

Cyber threat intelligence (CTI) is being used to search for indicators of attacks that might have compromised an enterprise network for a long time without being discovered. To hav…

cs.CR2018

ProPatrol: Attack Investigation via Extracted High-Level Tasks

Sadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo +1

Kernel audit logs are an invaluable source of information in the forensic investigation of a cyber-attack. However, the coarse granularity of dependency information in audit logs l…

cs.CR2018

HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows

Sadegh M. Milajerdi, Rigel Gjomemo, Birhanu Eshete +2

In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of…

cs.CR201892 cited

SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data

Md Nahid Hossain, Sadegh M Milajerdi, Junao Wang +5

We present an approach and system for real-time reconstruction of attack scenarios on an enterprise host. To meet the scalability and real-time needs of the problem, we develop a p…