OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMs
Fuente:
arXiv
Saved in:
| Main Authors: | Aly, Ahmed, Mansour, Essam, Youssef, Amr |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning
by: Lv, Mingqi, et al.
Published: (2024)
by: Lv, Mingqi, et al.
Published: (2024)
SAGA: Synthetic Audit Log Generation for APT Campaigns
by: Huang, Yi-Ting, et al.
Published: (2024)
by: Huang, Yi-Ting, et al.
Published: (2024)
RAPID: Robust APT Detection and Investigation Using Context-Aware Deep Learning
by: Amaru, Yonatan, et al.
Published: (2024)
by: Amaru, Yonatan, et al.
Published: (2024)
Attackers Strike Back? Not Anymore -- An Ensemble of RL Defenders Awakens for APT Detection
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
A Cascade Approach for APT Campaign Attribution in System Event Logs: Technique Hunting and Subgraph Matching
by: Huang, Yi-Ting, et al.
Published: (2024)
by: Huang, Yi-Ting, et al.
Published: (2024)
Advanced Persistent Threats (APT) Attribution Using Deep Reinforcement Learning
by: Basnet, Animesh Singh, et al.
Published: (2024)
by: Basnet, Animesh Singh, et al.
Published: (2024)
APT-MMF: An advanced persistent threat actor attribution method based on multimodal and multilevel feature fusion
by: Xiao, Nan, et al.
Published: (2024)
by: Xiao, Nan, et al.
Published: (2024)
Anomaly Detection in OKTA Logs using Autoencoders
by: Cain, Jericho, et al.
Published: (2024)
by: Cain, Jericho, et al.
Published: (2024)
APT-MCL: An Adaptive APT Detection System Based on Multi-View Collaborative Provenance Graph Learning
by: Lv, Mingqi, et al.
Published: (2026)
by: Lv, Mingqi, et al.
Published: (2026)
DeepStage: Learning Autonomous Defense Policies Against Multi-Stage APT Campaigns
by: Phan, Trung V., et al.
Published: (2026)
by: Phan, Trung V., et al.
Published: (2026)
Anomaly Detection in Certificate Transparency Logs
by: Ostertág, Richard, et al.
Published: (2024)
by: Ostertág, Richard, et al.
Published: (2024)
SHIELD: APT Detection and Intelligent Explanation Using LLM
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
From One Attack Domain to Another: Contrastive Transfer Learning with Siamese Networks for APT Detection
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
Knowledge Transfer from LLMs to Provenance Analysis: A Semantic-Augmented Method for APT Detection
by: Zuo, Fei, et al.
Published: (2025)
by: Zuo, Fei, et al.
Published: (2025)
A Novel GPT-Based Framework for Anomaly Detection in System Logs
by: Zhang, Zeng, et al.
Published: (2025)
by: Zhang, Zeng, et al.
Published: (2025)
Deep Learning-based Anomaly Detection and Log Analysis for Computer Networks
by: Wang, Shuzhan, et al.
Published: (2024)
by: Wang, Shuzhan, et al.
Published: (2024)
APT-LLM: Embedding-Based Anomaly Detection of Cyber Advanced Persistent Threats Using Large Language Models
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
Slot: Provenance-Driven APT Detection through Graph Reinforcement Learning
by: Qiao, Wei, et al.
Published: (2024)
by: Qiao, Wei, et al.
Published: (2024)
Generation of Human Comprehensible Access Control Policies from Audit Logs
by: Kumar, Gautam, et al.
Published: (2026)
by: Kumar, Gautam, et al.
Published: (2026)
CONTINUUM: Detecting APT Attacks through Spatial-Temporal Graph Neural Networks
by: Bahar, Atmane Ayoub Mansour, et al.
Published: (2025)
by: Bahar, Atmane Ayoub Mansour, et al.
Published: (2025)
Dual Explanations via Subgraph Matching for Malware Detection
by: Shokouhinejad, Hossein, et al.
Published: (2025)
by: Shokouhinejad, Hossein, et al.
Published: (2025)
APT-ClaritySet: A Large-Scale, High-Fidelity Labeled Dataset for APT Malware with Alias Normalization and Graph-Based Deduplication
by: Yin, Zhenhao, et al.
Published: (2025)
by: Yin, Zhenhao, et al.
Published: (2025)
TFLAG:Towards Practical APT Detection via Deviation-Aware Learning on Temporal Provenance Graph
by: Jiang, Wenhan, et al.
Published: (2025)
by: Jiang, Wenhan, et al.
Published: (2025)
LLM-Driven APT Detection for 6G Wireless Networks: A Systematic Review and Taxonomy
by: Golec, Muhammed, et al.
Published: (2025)
by: Golec, Muhammed, et al.
Published: (2025)
Bayesian Perspective on Memorization and Reconstruction
by: Kaplan, Haim, et al.
Published: (2025)
by: Kaplan, Haim, et al.
Published: (2025)
APT-Agent: Automated Penetration Testing using Large Language Models
by: Li, William Guanting, et al.
Published: (2026)
by: Li, William Guanting, et al.
Published: (2026)
Interpretable Anomaly-Based DDoS Detection in AI-RAN with XAI and LLMs
by: Chatzimiltis, Sotiris, et al.
Published: (2025)
by: Chatzimiltis, Sotiris, et al.
Published: (2025)
LogGuardQ: A Cognitive-Enhanced Reinforcement Learning Framework for Cybersecurity Anomaly Detection in Security Logs
by: de Sousa, Umberto Gonçalves
Published: (2025)
by: de Sousa, Umberto Gonçalves
Published: (2025)
Detecting APT Malware Command and Control over HTTP(S) Using Contextual Summaries
by: Alageel, Almuthanna, et al.
Published: (2025)
by: Alageel, Almuthanna, et al.
Published: (2025)
CICAPT-IIOT: A provenance-based APT attack dataset for IIoT environment
by: Ghiasvand, Erfan, et al.
Published: (2024)
by: Ghiasvand, Erfan, et al.
Published: (2024)
CALIBURN: A Regime-Sensitivity Study of Operationally Calibrated Streaming Intrusion Detection
by: Youssef, Michel A.
Published: (2026)
by: Youssef, Michel A.
Published: (2026)
Wavelet-Aware Anomaly Detection in Multi-Channel User Logs via Deviation Modulation and Resolution-Adaptive Attention
by: Kong, Kaichuan, et al.
Published: (2026)
by: Kong, Kaichuan, et al.
Published: (2026)
Adversarial Sample Generation for Anomaly Detection in Industrial Control Systems
by: Mustafa, Abdul, et al.
Published: (2025)
by: Mustafa, Abdul, et al.
Published: (2025)
Breaking Bad: Interpretability-Based Safety Audits of State-of-the-Art LLMs
by: Agarwal, Krishiv, et al.
Published: (2026)
by: Agarwal, Krishiv, et al.
Published: (2026)
TPPR: APT Tactic / Technique Pattern Guided Attack Path Reasoning for Attack Investigation
by: Sheng, Qi
Published: (2025)
by: Sheng, Qi
Published: (2025)
ProHunter: A Comprehensive APT Hunting System Based on Whole-System Provenance
by: Qiu, Xuebo, et al.
Published: (2026)
by: Qiu, Xuebo, et al.
Published: (2026)
Distributed Temporal Graph Learning with Provenance for APT Detection in Supply Chains
by: Tan, Zhuoran, et al.
Published: (2025)
by: Tan, Zhuoran, et al.
Published: (2025)
Detecting Sybil Addresses in Blockchain Airdrops: A Subgraph-based Feature Propagation and Fusion Approach
by: Liu, Qiangqiang, et al.
Published: (2025)
by: Liu, Qiangqiang, et al.
Published: (2025)
SD-CGAN: Conditional Sinkhorn Divergence GAN for DDoS Anomaly Detection in IoT Networks
by: Onyeka, Henry, et al.
Published: (2025)
by: Onyeka, Henry, et al.
Published: (2025)
Large Language Models for Detecting Cyberattacks on Smart Grid Protective Relays
by: Saber, Ahmad Mohammad, et al.
Published: (2026)
by: Saber, Ahmad Mohammad, et al.
Published: (2026)
Similar Items
-
TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning
by: Lv, Mingqi, et al.
Published: (2024) -
SAGA: Synthetic Audit Log Generation for APT Campaigns
by: Huang, Yi-Ting, et al.
Published: (2024) -
RAPID: Robust APT Detection and Investigation Using Context-Aware Deep Learning
by: Amaru, Yonatan, et al.
Published: (2024) -
Attackers Strike Back? Not Anymore -- An Ensemble of RL Defenders Awakens for APT Detection
by: Benabderrahmane, Sidahmed, et al.
Published: (2025) -
A Cascade Approach for APT Campaign Attribution in System Event Logs: Technique Hunting and Subgraph Matching
by: Huang, Yi-Ting, et al.
Published: (2024)