This is Why We Can’t Cache Nice Things: Lightning-Fast Threat Hunting using Suspicion-Based Hierarchical Storage

Author:

Hassan Wajih Ul1,Li Ding2,Jee Kangkook3,Yu Xiao4,Zou Kexuan5,Wang Dawei5,Chen Zhengzhang4,Li Zhichun4,Rhee Junghwan6,Gui Jiaping4,Bates Adam1

Affiliation:

1. University of Illinois at Urbana-Champaign, United States of America

2. Peking University, China

3. University of Texas at Dallas

4. NEC Laboratories America Inc., United States of America

5. University of Illinois at Urbana-Champaign

6. University of Central Oklahoma

Funder

National Science Foundation

Publisher

ACM

Reference74 articles.

1. [n.d.]. Cortex XDR. https://www.paloaltonetworks.com/cortex/cortex-xdr. [n.d.]. Cortex XDR. https://www.paloaltonetworks.com/cortex/cortex-xdr.

2. [n.d.]. CrowdStrike. https://www.crowdstrike.com/. [n.d.]. CrowdStrike. https://www.crowdstrike.com/.

3. [n.d.]. Event tracing. https://docs.microsoft.com/en-us/windows/desktop/ETW/event-tracing-portal. [n.d.]. Event tracing. https://docs.microsoft.com/en-us/windows/desktop/ETW/event-tracing-portal.

4. [n.d.]. The Linux audit daemon. https://linux.die.net/man/8/auditd. [n.d.]. The Linux audit daemon. https://linux.die.net/man/8/auditd.

5. [n.d.]. MTTD vs MTTK. https://www.threatstack.com/blog/how-to-use-automation-to-decrease-mean-time-to-know. [n.d.]. MTTD vs MTTK. https://www.threatstack.com/blog/how-to-use-automation-to-decrease-mean-time-to-know.

Cited by 9 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. ProcSAGE: an efficient host threat detection method based on graph representation learning;Cybersecurity;2024-08-25

2. MEGR-APT: A Memory-Efficient APT Hunting System Based on Attack Representation Learning;IEEE Transactions on Information Forensics and Security;2024

3. ProvG-Searcher: A Graph Representation Learning Approach for Efficient Provenance Graph Search;Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security;2023-11-15

4. ProvSec: Open Cybersecurity System Provenance Analysis Benchmark Dataset with Labels;International Journal of Networked and Distributed Computing;2023-11-15

5. ProvSec: Cybersecurity System Provenance Analysis Benchmark Dataset;2023 IEEE/ACIS 21st International Conference on Software Engineering Research, Management and Applications (SERA);2023-05-23

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3