发表机构
Purdue University; IBM Research; UMass Amherst(普渡大学; IBM研究院; 马萨诸塞大学阿默斯特分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出DUPIN方法,先对海量审计事件做无监督预训练,再用少量带标签攻击示例微调检测能力,经25个APT攻击活动评估,其作为灵活取证学习者表现良好。
AI 中文摘要
我们提出一种名为DUPIN的新型基于学习的攻击取证方法。DUPIN以溯源图形式对海量审计事件执行无监督预训练,随后进入少样本学习阶段,利用少量带标签的攻击示例微调其检测能力。我们在长达38-52天的审计日志(总计7.3TB)上预训练DUPIN,并针对四个不同数据源的25个APT攻击活动,在多种基准方法上对其进行评估,以实现可扩展评估。
英文摘要
We propose a novel approach to learning-based attack forensics called DUPIN. DUPIN performs unsupervised pre-training on an enormous amount of audit events in the form of provenance graphs. It then proceeds to a few-shot learning stage, leveraging a small number of labeled attack examples to fine-tune its detection capabilities. We pretrain DUPIN on up to 38 - 52 days of audit logs (7.3TB total) and evaluate it against various baselines on 25 APT campaigns across four different data sources, facilitating the scalable evaluation.
Journal ref35th USENIX Security Symposium (USENIX Security 2026)