arXiv · 2111.05764
A framework for comprehensible multi-modal detection of cyber threats
Abstract
Detection of malicious activities in corporate environments is a very complex task and much effort has been invested into research of its automation. However, vast majority of existing methods operate only in a narrow scope which limits them to capture only fragments of the evidence of malware's presence. Consequently, such approach is not aligned with the way how the cyber threats are studied and described by domain experts. In this work, we discuss these limitations and design a detection framework which combines observed events from different sources of data. Thanks to this, it provides full insight into the attack life cycle and enables detection of threats that require this coupling of observations from different telemetries to identify the full scope of the incident. We demonstrate applicability of the framework on a case study of a real malware infection observed in a corporate network.
Explore related subjects
Keep this discovery
Jan Kohout, Čeněk Škarda, Kyrylo Shcherbin, Martin Kopp, Jan Brabec. 2021-11-10. A framework for comprehensible multi-modal detection of cyber threats. https://arxiv.org/abs/2111.05764
Cite the original work for its findings. Save a collection to share your selection of sources.