Unified Semantic Log Parsing and Causal Graph Construction for Attack Attribution

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Tan, Zhuoran, Anagnostopoulos, Christos, Parambath, Shameem P., Singer, Jeremy
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913583867101184
author Tan, Zhuoran
Anagnostopoulos, Christos
Parambath, Shameem P.
Singer, Jeremy
author_facet Tan, Zhuoran
Anagnostopoulos, Christos
Parambath, Shameem P.
Singer, Jeremy
contents Multi-source logs provide a comprehensive overview of ongoing system activities, allowing for in-depth analysis to detect potential threats. A practical approach for threat detection involves explicit extraction of entity triples (subject, action, object) towards building provenance graphs to facilitate the analysis of system behavior. However, current log parsing methods mainly focus on retrieving parameters and events from raw logs while approaches based on entity extraction are limited to processing a single type of log. To address these gaps, we contribute with a novel unified framework, coined UTLParser. UTLParser adopts semantic analysis to construct causal graphs by merging multiple sub-graphs from individual log sources in labeled log dataset. It leverages domain knowledge in threat hunting such as Points of Interest. We further explore log generation delays and provide interfaces for optimized temporal graph querying. Our experiments showcase that UTLParser overcomes drawbacks of other log parsing methods. Furthermore, UTLParser precisely extracts explicit causal threat information while being compatible with enormous downstream tasks.
format Preprint
id arxiv_https___arxiv_org_abs_2411_15354
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Unified Semantic Log Parsing and Causal Graph Construction for Attack Attribution
Tan, Zhuoran
Anagnostopoulos, Christos
Parambath, Shameem P.
Singer, Jeremy
Software Engineering
Multi-source logs provide a comprehensive overview of ongoing system activities, allowing for in-depth analysis to detect potential threats. A practical approach for threat detection involves explicit extraction of entity triples (subject, action, object) towards building provenance graphs to facilitate the analysis of system behavior. However, current log parsing methods mainly focus on retrieving parameters and events from raw logs while approaches based on entity extraction are limited to processing a single type of log. To address these gaps, we contribute with a novel unified framework, coined UTLParser. UTLParser adopts semantic analysis to construct causal graphs by merging multiple sub-graphs from individual log sources in labeled log dataset. It leverages domain knowledge in threat hunting such as Points of Interest. We further explore log generation delays and provide interfaces for optimized temporal graph querying. Our experiments showcase that UTLParser overcomes drawbacks of other log parsing methods. Furthermore, UTLParser precisely extracts explicit causal threat information while being compatible with enormous downstream tasks.
title Unified Semantic Log Parsing and Causal Graph Construction for Attack Attribution
topic Software Engineering
url https://arxiv.org/abs/2411.15354