发表机构
University of Calabria(卡拉布里亚大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出Trace2ATT&CK方法,利用eBPF收集内核事件构建溯源图,结合LLM与RAG映射到MITRE ATT&CK,在347个测试上验证了图表示和RAG的优越性,实现不泄露数据的自动化映射。
AI 中文摘要
将观察到的系统行为映射到如MITRE ATT&CK等标准化框架对于威胁知情防御至关重要,但这一过程在很大程度上仍依赖人工操作。现有的自动化方法依赖于网络威胁情报报告,而这些报告仅提供对攻击的事后描述。低层遥测,即内核级系统调用,反而提供了对手行为的证据,但其规模和复杂性限制了其在自动化映射中的应用。我们提出了一种方法,通过eBPF收集内核级事件,将攻击者命令关联成溯源图,并推导出适合基于LLM推理的紧凑图表示。这些表示通过纯LLM提示和基于ATT&CK知识库的检索增强生成(RAG)映射到MITRE ATT&CK框架,生成排序的技术候选及其支持理由。我们将此方法实现为一个端到端流水线,命名为Trace2ATT&CK,并使用本地部署的开源权重LLM在347个Linux Atomic Red Team测试上进行了评估。RAG在ATT&CK映射性能上始终优于纯提示,而溯源图显著优于原始遥测。这些结果表明,基于图的本地推理行为描述可以使从内核级遥测进行自动化ATT&CK映射在操作上可行,且不损害数据机密性。
英文摘要
Mapping observed system behavior to standardized frameworks like MITRE ATT&CK is essential for threat-informed defense, but remains largely manual. Existing automated methods depend on Cyber Threat Intelligence reports, which offer only retrospective accounts of attacks. Low-level telemetry, i.e. kernel-level system calls, instead provides evidence of adversary behavior, yet its volume and complexity have limited its use for automated mapping. We present a methodology that collects kernel-level events via eBPF, correlates attacker commands into a provenance graph, and derives compact graph representations suitable for LLM-based reasoning. These representations are mapped to the MITRE ATT&CK framework using both pure LLM prompting and retrieval-augmented generation (RAG) grounded in the ATT&CK knowledge base, producing ranked technique candidates along with supporting rationales. We implement this methodology as an end-to-end pipeline, named Trace2ATT&CK and evaluate it on 347 Linux Atomic Red Team tests using locally deployed open-weights LLMs. RAG consistently improves ATT&CK mapping performance over pure prompting, while provenance graph substantially outperforms raw telemetry. These results show that local inference over graph-based behavioral descriptions can make automated ATT&CK mapping from kernel-level telemetry operationally viable, without compromising data confidentiality.