paper-with-me

홈 › Papers

Enabling Efficient Cyber Threat Hunting With Cyber Threat Intelligence

2020-10-26 · Peng Gao, Fei Shao, Xiaoyuan Liu, Xusheng Xiao, Zheng Qin, Fengyuan Xu, Prateek Mittal, Sanjeev R. Kulkarni, Dawn Song

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the rich external threat knowledge provided by open-source Cyber Threat Intelligence (OSCTI). To bridge the gap, we propose ThreatRaptor, a system that facilitates threat hunting in computer systems using OSCTI. Built upon system auditing frameworks, ThreatRaptor provides (1) an unsupervised, light-weight, and accurate NLP pipeline that extracts structured threat behaviors from unstructured OSCTI text, (2) a concise and expressive domain-specific query language, TBQL, to hunt for malicious system activities, (3) a query synthesis mechanism that automatically synthesizes a TBQL query for hunting, and (4) an efficient query execution engine to search the big audit logging data. Evaluations on a broad set of attack cases demonstrate the accuracy and efficiency of ThreatRaptor in practical threat hunting.

📄 PDF Abstract BibTeX arXiv:2010.13637

Code (1)

seclab-vt/threatraptor 공식 구현

Similar Papers 제목 키워드 기반

Benchmarking LLM-Assisted Blue Teaming via Standardized Threat Hunting

2025-09-28 · Yuqiao Meng, Luoxi Tang, Feiyang Yu, Xi Li 외 arxiv

As cyber threats continue to grow in scale and sophistication, blue team defenders increasingly require advanced tools to proactively detect and mitigate risks. Large Language Models (LLMs) offer promising capabilities f…

A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence

2021-01-17 · Peng Gao, Fei Shao, Xiaoyuan Liu, Xusheng Xiao 외

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated cyber attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the ri…

Evidential Cyber Threat Hunting

2021-04-21 · Frederico Araujo, Dhilung Kirat, Xiaokui Shu, Teryl Taylor 외

A formal cyber reasoning framework for automating the threat hunting process is described. The new cyber reasoning methodology introduces an operational semantics that operates over three subspaces -- knowledge, hypothes…

Automating Cyber Threat Hunting Using NLP, Automated Query Generation, and Genetic Perturbation

2021-04-23 · Prakruthi Karuna, Erik Hemberg, Una-May O'Reilly, Nick Rutar

Scaling the cyber hunt problem poses several key technical challenges. Detecting and characterizing cyber threats at scale in large enterprise networks is hard because of the vast quantity and complexity of the data that…

Technique Inference Engine: A Recommender Model to Support Cyber Threat Hunting

2025-03-04 · Matthew J. Turner, Mike Carenzo, Jackie Lasky, James Morris-King 외

Cyber threat hunting is the practice of proactively searching for latent threats in a network. Engaging in threat hunting can be difficult due to the volume of network traffic, variety of adversary techniques, and consta…