ADAPTD:针对自主高级持续性威胁攻击的自适应检测与主动防御
ADAPTD: Adaptive Detection and Proactive Threat Defense for Autonomous APT attacks
AI总结:
ADAPTD是一种通信与计算高效的决策论框架,通过整合紧凑杀伤链、即时阻断机制和预测性驱逐策略,在自主APT攻击检测防御中实现了优于现有方法的效果,降低了防御成本与干扰。
AI中文摘要:
高级持续性威胁(APT)攻击者越来越多地采用复杂技术在分段企业网络中横向传播。及时检测与防御依赖跨子网协调,但维持全局态势感知会产生大量通信开销。为平衡该问题,灵活监测与自适应遏制至关重要。本文提出ADAPTD,一种通信与计算高效的决策论框架,整合了:(i)用于识别各类攻击向量的紧凑杀伤链;(ii)用于及时遏制的即时阻断机制;(iii)用于恢复系统安全的预测性驱逐策略。实验在各类威胁场景中验证了ADAPTD的有效性:首先,我们的去中心化信念更新方案优于最先进的扩散隐马尔可夫模型(HMM);其次,ADAPTD与基于Transformer的检测相比大幅减少了误驱逐;第三,在有噪声的环境中,自适应阻断可遏制攻击者同时将不必要的干扰降至最低;最后, ablation研究证实,结合两种防御行动可显著降低防御者的总成本。
英文摘要:
Advanced persistent threat (APT) actors increasingly employ sophisticated techniques to propagate laterally through segmented enterprise networks. Timely detection and defense depend on cross-subnetwork coordination, yet maintaining global situational awareness generates substantial communication overhead. To manage this tradeoff, flexible monitoring and adaptable containment are imperative. This paper presents ADAPTD, a communication- and computation-efficient, decision-theoretic framework integrating: (i) compact kill chains for identifying diverse attack vectors, (ii) an immediate blocking mechanism for timely containment, and (iii) a predictive eviction strategy to restore system security. Our experiments validate ADAPTD's effectiveness across diverse threat scenarios. First, our decentralized belief update scheme outperforms state-of-the-art diffusion HMM. Second, ADAPTD substantially reduces false evictions compared to transformer-based detection. Third, under noisy environments, adaptive blocking contains attackers while minimizing unnecessary disruption. Lastly, the ablation study confirms that combining two defensive actions significantly reduces the defender's total cost.