Tactical Provenance Analysis for Endpoint Detection and Response Systems

被引:140
作者
Ul Hassan, Wajih [1 ]
Bates, Adam [1 ]
Marino, Daniel [2 ]
机构
[1] Univ Illinois, Champaign, IL 61820 USA
[2] NortonLifeLock, Res Grp, Tempe, AZ USA
来源
2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020) | 2020年
关键词
D O I
10.1109/SP40000.2020.00096
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Endpoint Detection and Response (EDR) tools provide visibility into sophisticated intrusions by matching system events against known adversarial behaviors. However, current solutions suffer from three challenges: 1) EDR tools generate a high volume of false alarms, creating backlogs of investigation tasks for analysts; 2) determining the veracity of these threat alerts requires tedious manual labor due to the overwhelming amount of low-level system logs, creating a "needle-in-a-haystack" problem; and 3) due to the tremendous resource burden of log retention, in practice the system logs describing long-lived attack campaigns are often deleted before an investigation is ever initiated. This paper describes an effort to bring the benefits of data provenance to commercial EDR tools. We introduce the notion of Tactical Provenance Graphs (TPGs) that, rather than encoding low-level system event dependencies, reason about causal dependencies between EDR-generated threat alerts. TPGs provide compact visualization of multi-stage attacks to analysts, accelerating investigation. To address EDR's false alarm problem, we introduce a threat scoring methodology that assesses risk based on the temporal ordering between individual threat alerts present in the TPG. In contrast to the retention of unwieldy system logs, we maintain a minimally-sufficient skeleton graph that can provide linkability between existing and future threat alerts. We evaluate our system, RapSheet, using the Symantec EDR tool in an enterprise environment. Results show that our approach can rank truly malicious TPGs higher than false alarm TPGs. Moreover, our skeleton graph reduces the long-term burden of log retention by up to 87%.
引用
收藏
页码:1172 / 1189
页数:18
相关论文
共 73 条
[1]  
Airbus Cyber Security, 2018, APT KILL CHAIN
[2]  
[Anonymous], 2017, USENIX SECURITY
[3]  
[Anonymous], 2019, THREAT BASED DEFENSE
[4]  
[Anonymous], 2019, REDISGRAPH GRAPH DAT
[5]  
[Anonymous], 2019, ATT&CK: Scripting
[6]  
[Anonymous], 2019, Automated Incident Response: Respond to Every Alert
[7]  
[Anonymous], 2019, Technical Report.
[8]  
[Anonymous], 2017, MONITORING ALPC MESS
[9]  
[Anonymous], 2018, EVALUATING ENDPOINT
[10]  
[Anonymous], 2019, PURGING REPORTS