arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.21303cs.CRcs.LG

利用机器学习识别安全平台产品滥用

Identifying Security Platform Product Abuse with Machine Learning

发表机构CrowdStrike公司
查看机构详情
  • CrowdStrike(CrowdStrike公司)

机构由 AI 辅助整理,请以论文原文为准。

Shaefer Drew, Michael Brautbar, Paul Knight, Edward Raff, Lana Peric-McDermott, Simran Sarin, Nickolas Machado, Hanna Albright, Vitaly Zaytsev

首次发表
浏览论文内容

中文总结 AI 辅助

本研究首次提出并评估了针对SaaS安全平台产品滥用的全系统机器学习防御,通过多模态数据收集和冷启动处理,实现了覆盖率提升35%和警报减少30%。

中文摘要 AI 辅助

产品滥用是SaaS行业中一种个体罕见但日益增长的问题。高度复杂的威胁行为者可以在客户环境中滥用安全平台,或对产品本身进行绕过实验。威胁行为者可以利用离地攻击(LOTL)来避免使用笨重且经常被检测到的恶意软件。修复这一威胁需要跨不同类型数据库收集多种数据模态,解决此类复杂但危险事件内在稀缺性带来的冷启动问题,并在现实部署的约束(如成本、用户行为、性能等)内进行设计。为此,我们提供了首次针对此类全系统防御的研究,特别是针对已部署且可运行的能力。我们的结果显示,产品滥用覆盖率提高了35%,月度警报减少了30%,并且能够适应恶意行为者行为的变化。我们回顾了在设计系统以满足运营要求时所考虑的约束,以及对可解释特征价值和先前识别攻击的反事实性能的回顾性评估。

英文摘要

Product abuse is an individually rare, but growing, problem across the SaaS industry. Highly sophisticated threat actors can misuse security platforms within customer environments or conduct bypass experiments on the product itself. Threat actors can leverage living-off-the-land (LOTL) attacks to avoid using cumbersome, frequently detected malware. Remediating this threat requires collecting multiple data modalities across different types of databases, addressing a cold-start problem in the intrinsic rarity of such sophisticated but dangerous events, and designing within the constraints of real-world deployment (e.g., cost, user behavior, performance, etc). To wit, we provide the first study of such a whole-system defense, especially with respect to a deployed and operational capability. Our results show an increase in product abuse coverage by 35\%, a 30\% reduction in monthly alerts, and adaptability to changes in malicious actors' behavior. We review both the constraints we considered in designing the system to meet operational requirements and a retrospective evaluation of the value of explainable features and counterfactual performance on previously identified attacks.

补充信息

↑