了解正常行为,追踪攻击:基于系统溯源的情境感知与状态化LLM调查
Know the Normal, Track the Attack: Context-Grounded and Stateful LLM Investigation over System Provenance
浏览论文内容
中文总结 AI 辅助
提出ANCHOR系统,结合证据策展与情境感知LLM推理,利用部署和案例情境校准异常并维护攻击状态,在DARPA数据集上提升IoC恢复和攻击阶段归因。
中文摘要 AI 辅助
基于溯源的入侵检测系统(PIDSs)在审计流中识别可疑活动,但其输出难以转化为连贯的攻击叙事。直接对局部异常子图进行LLM分析缺乏部署特定的正常行为知识以及跨证据片段的已验证攻击状态。这可能导致对常规活动的无根据攻击解释,以及将时间上分散的证据错误归因于攻击阶段。我们提出ANCHOR,一个面向调查的溯源系统,结合证据策展与情境感知的LLM推理。它通过关系类型校准异常判断,并通过罕见关系-角色模式链接异常窗口。由此产生的证据队列保留了因果结构、时间边界和跨窗口连续性。调查器使用两种互补的情境形式来解释以进程为中心的证据。部署情境将环境特定的交互和对象基线同高风险安全知识相结合。案例情境使用置信门控的攻击追踪缓存来维护跨窗口的调查状态。通过将当前证据与高置信度的先前发现相关联,ANCHOR逐步重建按杀伤链阶段组织的攻击叙事。我们在六个DARPA透明计算E3/E5数据集上评估ANCHOR,涵盖三个操作系统。受控的证据级和端到端比较显示,在状态最先进的基于溯源的基线上,整体IoC恢复和攻击阶段归因有所改进。在我们的评估中,这些增益在固定LLM骨干下持续存在。ANCHOR以美元级API成本处理完整审计日,支持跨窗口的实用、情境感知调查。
英文摘要
Provenance-based intrusion detection systems (PIDSs) identify suspicious activity in audit streams, but their outputs remain difficult to turn into coherent attack narratives. Direct LLM analyses of local anomalous subgraphs lack deployment-specific normal-behavior knowledge and validated attack state across evidence fragments. This can cause unsupported attack interpretations of routine activities and incorrect attribution of temporally dispersed evidence to attack stages. We present ANCHOR, an investigation-oriented provenance system that combines evidence curation with context-grounded LLM reasoning. It calibrates anomaly judgments by relation type and links anomalous windows through rare relation-role patterns. The resulting evidence queues preserve causal structure, temporal boundaries, and cross-window continuity. The investigator interprets process-centered evidence using two complementary forms of context. Deployment Context combines environment-specific interaction and object baselines with high-risk security knowledge. Case Context uses a confidence-gated Attack-Tracking Cache to maintain investigation state across windows. Correlating current evidence with high-confidence prior findings, ANCHOR incrementally reconstructs attack narratives organized by kill-chain stages. We evaluate ANCHOR on six DARPA Transparent Computing E3/E5 datasets across three operating systems. Controlled evidence-level and end-to-end comparisons show improved overall IoC recovery and attack-stage attribution over state-of-the-art provenance-based baselines. These gains persist under a fixed LLM backbone in our evaluation. ANCHOR processes a full audit day at dollar-level API cost, supporting practical, context-grounded investigation across windows.
发表机构
- Xidian University(西安电子科技大学)
机构由 AI 辅助整理,请以论文原文为准。