Marlin: Knowledge-Driven Analysis of Provenance Graphs for Efficient and Robust Detection of Cyber Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Zhenyuan, Wei, Yangyang, Shen, Xiangmin, Wang, Lingzhi, Chen, Yan, Xu, Haitao, Ji, Shouling, Zhang, Fan, Hou, Liang, Liu, Wenmao, Zhang, Xuhong, Ying, Jianwei
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910521037422592
author Li, Zhenyuan
Wei, Yangyang
Shen, Xiangmin
Wang, Lingzhi
Chen, Yan
Xu, Haitao
Ji, Shouling
Zhang, Fan
Hou, Liang
Liu, Wenmao
Zhang, Xuhong
Ying, Jianwei
author_facet Li, Zhenyuan
Wei, Yangyang
Shen, Xiangmin
Wang, Lingzhi
Chen, Yan
Xu, Haitao
Ji, Shouling
Zhang, Fan
Hou, Liang
Liu, Wenmao
Zhang, Xuhong
Ying, Jianwei
contents Recent research in both academia and industry has validated the effectiveness of provenance graph-based detection for advanced cyber attack detection and investigation. However, analyzing large-scale provenance graphs often results in substantial overhead. To improve performance, existing detection systems implement various optimization strategies. Yet, as several recent studies suggest, these strategies could lose necessary context information and be vulnerable to evasions. Designing a detection system that is efficient and robust against adversarial attacks is an open problem. We introduce Marlin, which approaches cyber attack detection through real-time provenance graph alignment.By leveraging query graphs embedded with attack knowledge, Marlin can efficiently identify entities and events within provenance graphs, embedding targeted analysis and significantly narrowing the search space. Moreover, we incorporate our graph alignment algorithm into a tag propagation-based schema to eliminate the need for storing and reprocessing raw logs. This design significantly reduces in-memory storage requirements and minimizes data processing overhead. As a result, it enables real-time graph alignment while preserving essential context information, thereby enhancing the robustness of cyber attack detection. Moreover, Marlin allows analysts to customize attack query graphs flexibly to detect extended attacks and provide interpretable detection results. We conduct experimental evaluations on two large-scale public datasets containing 257.42 GB of logs and 12 query graphs of varying sizes, covering multiple attack techniques and scenarios. The results show that Marlin can process 137K events per second while accurately identifying 120 subgraphs with 31 confirmed attacks, along with only 1 false positive, demonstrating its efficiency and accuracy in handling massive data.
format Preprint
id arxiv_https___arxiv_org_abs_2403_12541
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Marlin: Knowledge-Driven Analysis of Provenance Graphs for Efficient and Robust Detection of Cyber Attacks
Li, Zhenyuan
Wei, Yangyang
Shen, Xiangmin
Wang, Lingzhi
Chen, Yan
Xu, Haitao
Ji, Shouling
Zhang, Fan
Hou, Liang
Liu, Wenmao
Zhang, Xuhong
Ying, Jianwei
Cryptography and Security
Recent research in both academia and industry has validated the effectiveness of provenance graph-based detection for advanced cyber attack detection and investigation. However, analyzing large-scale provenance graphs often results in substantial overhead. To improve performance, existing detection systems implement various optimization strategies. Yet, as several recent studies suggest, these strategies could lose necessary context information and be vulnerable to evasions. Designing a detection system that is efficient and robust against adversarial attacks is an open problem. We introduce Marlin, which approaches cyber attack detection through real-time provenance graph alignment.By leveraging query graphs embedded with attack knowledge, Marlin can efficiently identify entities and events within provenance graphs, embedding targeted analysis and significantly narrowing the search space. Moreover, we incorporate our graph alignment algorithm into a tag propagation-based schema to eliminate the need for storing and reprocessing raw logs. This design significantly reduces in-memory storage requirements and minimizes data processing overhead. As a result, it enables real-time graph alignment while preserving essential context information, thereby enhancing the robustness of cyber attack detection. Moreover, Marlin allows analysts to customize attack query graphs flexibly to detect extended attacks and provide interpretable detection results. We conduct experimental evaluations on two large-scale public datasets containing 257.42 GB of logs and 12 query graphs of varying sizes, covering multiple attack techniques and scenarios. The results show that Marlin can process 137K events per second while accurately identifying 120 subgraphs with 31 confirmed attacks, along with only 1 false positive, demonstrating its efficiency and accuracy in handling massive data.
title Marlin: Knowledge-Driven Analysis of Provenance Graphs for Efficient and Robust Detection of Cyber Attacks
topic Cryptography and Security
url https://arxiv.org/abs/2403.12541