Pattern Extraction for Behaviours of Multi-Stage Threats via Unsupervised Learning

No ratings

Presented at CyberScience2020 2020 by

Detection of multi-stage threats such as Advanced Persistent Threats (APT) is extremely challenging dueto their deceptive approaches. Sequential events of threats might look benign when performed individually or fromdifferent addresses. We propose a new unsupervised framework to identify patterns and correlations of maliciousbehaviours by analysing heterogeneous log-files. The framework consists of two main phases of data analysis toextract inner-behaviours of log-files and then the patterns of those behaviours over analysed files. To evaluate theframework we have produced a (publicly available) labelled version of the SotM43 dataset. Our results demonstratethat the framework can (i) efficiently cluster inner-behaviours of log-files with high accuracy and (ii) extract patternsof malicious behaviour and correlations between those patterns from real-world data.