跳到主要导航 跳到搜索 跳到主要内容

MuSAR: Multi-Step Attack Reconstruction from Lightweight Security Logs via Event-Level Semantic Association in Multi-Host Environments

  • Yang Liu
  • , Zisen Xu
  • , Zian Luo
  • , Jin'Ao Shang
  • , Shilong Zhang
  • , Haichuan Zhang
  • , Ting Liu
  • Xi'an Jiaotong University
  • University of Science and Technology of China

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Multi-step attacks challenge security analysts in reconstructing attack sequences from extensive multi-host log data. Existing attack reconstruction approaches rely heavily on computationally intensive audit logs and provenance analysis, limiting their practicality in multi-host environments. We present MuSAR, a framework for real-time reconstruction of multi-step attacks in multi-host environments using lightweight security logs (network alarms and application logs). First, security logs are consolidated into inter-host and intra-host security events through semantic analysis, respectively. Then, these security events are mapped to unified attack lifecycle stages through MITRE ATTACK framework integration. Finally, a heuristic algorithm is implemented to identify potential multi-step attacks and reconstruct complete attack sequences based on event-level semantic associations. Evaluation on the CPTC2018 dataset and a multi-step attack simulation dataset demonstrates MuSAR's effectiveness in identifying attack-related traces and reconstructing multi-step attacks, achieving an average recall of 93.48% and F1-score of 94.39%, respectively, outperforming state-of-the-art methods in attack investigation and reconstruction in multi-host environments.

源语言英语
主期刊名Proceedings - 28th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2025
出版商Institute of Electrical and Electronics Engineers Inc.
329-348
页数20
ISBN(电子版)9798331566036
DOI
出版状态已出版 - 2025
活动28th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2025 - Gold Coast, 澳大利亚
期限: 19 10月 202522 10月 2025

出版系列

姓名Proceedings - 28th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2025

会议

会议28th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2025
国家/地区澳大利亚
Gold Coast
时期19/10/2522/10/25

学术指纹

探究 'MuSAR: Multi-Step Attack Reconstruction from Lightweight Security Logs via Event-Level Semantic Association in Multi-Host Environments' 的科研主题。它们共同构成独一无二的指纹。

引用此