论文标题

Athafi:敏捷威胁狩猎和法医调查

ATHAFI: Agile Threat Hunting And Forensic Investigation

论文作者

Puzis, Rami, Zilberman, Polina, Elovici, Yuval

论文摘要

攻击者迅速改变攻击以逃避检测。即使是基于人工智能和高级数据分析的最复杂的入侵检测系统,也无法与新攻击的快速发展保持同步。当标准检测机制失败或不提供足够的法医信息来调查和减轻攻击时,会使用主管人员进行的目标威胁狩猎。不幸的是,许多组织没有足够的安全分析师来执行威胁狩猎任务,如今,威胁狩猎的自动化水平很低。 在本文中,我们描述了一个敏捷威胁狩猎和法医调查(ATHAFI)的框架,该框架在多个层面上自动化威胁狩猎过程。自适应目标数据收集,攻击假设生成,假设测试以及持续的威胁智能提要可以以完全自动化的方式进行简单的调查。在调查最严厉的案例期间,自动化水平的提高将显着提高分析师的生产率。 特殊的工作流生成模块将威胁狩猎程序适应从外部来源获得的最新威胁情报(例如国家证书),或者是攻击假设生成模块产生的最有可能的攻击假设。攻击假设生成和工作流程的结合使工作流程的智能调整可以有效地对新兴威胁做出反应。

Attackers rapidly change their attacks to evade detection. Even the most sophisticated Intrusion Detection Systems that are based on artificial intelligence and advanced data analytic cannot keep pace with the rapid development of new attacks. When standard detection mechanisms fail or do not provide sufficient forensic information to investigate and mitigate attacks, targeted threat hunting performed by competent personnel is used. Unfortunately, many organization do not have enough security analysts to perform threat hunting tasks and today the level of automation of threat hunting is low. In this paper we describe a framework for agile threat hunting and forensic investigation (ATHAFI), which automates the threat hunting process at multiple levels. Adaptive targeted data collection, attack hypotheses generation, hypotheses testing, and continuous threat intelligence feeds allow to perform simple investigations in a fully automated manner. The increased level of automation will significantly boost the analyst's productivity during investigation of the harshest cases. Special Workflow Generation module adapts the threat hunting procedures either to the latest Threat Intelligence obtained from external sources (e.g. National CERT) or to the likeliest attack hypotheses generated by the Attack Hypotheses Generation module. The combination of Attack Hypotheses Generation and Workflows Generation enables intelligent adjustment of workflows, which react to emerging threats effectively.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源