Attack Effect Model based Malicious Behavior Detection

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Wang, Limin, Bu, Lei, Zhang, Muzimiao, Cang, Shihong, Ye, Kai
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910989477216256
author Wang, Limin
Bu, Lei
Zhang, Muzimiao
Cang, Shihong
Ye, Kai
author_facet Wang, Limin
Bu, Lei
Zhang, Muzimiao
Cang, Shihong
Ye, Kai
contents Traditional security detection methods face three key challenges: inadequate data collection that misses critical security events, resource-intensive monitoring systems, and poor detection algorithms with high false positive rates. We present FEAD (Focus-Enhanced Attack Detection), a framework that addresses these issues through three innovations: (1) an attack model-driven approach that extracts security-critical monitoring items from online attack reports for comprehensive coverage; (2) efficient task decomposition that optimally distributes monitoring across existing collectors to minimize overhead; and (3) locality-aware anomaly analysis that leverages the clustering behavior of malicious activities in provenance graphs to improve detection accuracy. Evaluations demonstrate FEAD achieves 8.23% higher F1-score than existing solutions with only 5.4% overhead, confirming that focus-based designs significantly enhance detection performance.
format Preprint
id arxiv_https___arxiv_org_abs_2506_05001
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Attack Effect Model based Malicious Behavior Detection
Wang, Limin
Bu, Lei
Zhang, Muzimiao
Cang, Shihong
Ye, Kai
Cryptography and Security
Traditional security detection methods face three key challenges: inadequate data collection that misses critical security events, resource-intensive monitoring systems, and poor detection algorithms with high false positive rates. We present FEAD (Focus-Enhanced Attack Detection), a framework that addresses these issues through three innovations: (1) an attack model-driven approach that extracts security-critical monitoring items from online attack reports for comprehensive coverage; (2) efficient task decomposition that optimally distributes monitoring across existing collectors to minimize overhead; and (3) locality-aware anomaly analysis that leverages the clustering behavior of malicious activities in provenance graphs to improve detection accuracy. Evaluations demonstrate FEAD achieves 8.23% higher F1-score than existing solutions with only 5.4% overhead, confirming that focus-based designs significantly enhance detection performance.
title Attack Effect Model based Malicious Behavior Detection
topic Cryptography and Security
url https://arxiv.org/abs/2506.05001