paper-with-me

홈 › Papers

Kairos: Practical Intrusion Detection and Investigation using Whole-system Provenance

2023-08-09 · Zijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang, Degang Sun, Thomas Pasquier, Xueyuan Han

Provenance graphs are structured audit logs that describe the history of a system's execution. Recent studies have explored a variety of techniques to analyze provenance graphs for automated host intrusion detection, focusing particularly on advanced persistent threats. Sifting through their design documents, we identify four common dimensions that drive the development of provenance-based intrusion detection systems (PIDSes): scope (can PIDSes detect modern attacks that infiltrate across application boundaries?), attack agnosticity (can PIDSes detect novel attacks without a priori knowledge of attack characteristics?), timeliness (can PIDSes efficiently monitor host systems as they run?), and attack reconstruction (can PIDSes distill attack activity from large provenance graphs so that sysadmins can easily understand and quickly respond to system intrusion?). We present KAIROS, the first PIDS that simultaneously satisfies the desiderata in all four dimensions, whereas existing approaches sacrifice at least one and struggle to achieve comparable detection performance. Kairos leverages a novel graph neural network-based encoder-decoder architecture that learns the temporal evolution of a provenance graph's structural changes to quantify the degree of anomalousness for each system event. Then, based on this fine-grained information, Kairos reconstructs attack footprints, generating compact summary graphs that accurately describe malicious activity over a stream of system audit logs. Using state-of-the-art benchmark datasets, we demonstrate that Kairos outperforms previous approaches.

📄 PDF Abstract BibTeX arXiv:2308.05034

Code (1)

provenanceanalytics/kairos 공식 구현 pytorch

Tasks

DecoderGraph Neural NetworkIntrusion Detection

Similar Papers 제목 키워드 기반

KairosAD: A SAM-Based Model for Industrial Anomaly Detection on Embedded Devices

2025-05-30 · Uzair Khan, Franco Fummi, Luigi Capogrosso

In the era of intelligent manufacturing, anomaly detection has become essential for maintaining quality control on modern production lines. However, while many existing models show promising performance, they are often t…

Anomaly Detection

PROVEX: Enhancing SOC Analyst Trust with Explainable Provenance-Based IDS

2025-12-20 · Devang Dhanuka, Nidhi Rastogi arxiv

Modern intrusion detection systems (IDS) leverage graph neural networks (GNNs) to detect malicious activity in system provenance data, but their decisions often remain a black box to analysts. This paper presents a compr…

Intrusion Detection

Improving Transferability of Network Intrusion Detection in a Federated Learning Setup

2024-01-07 · Shreya Ghosh, Abu Shafin Mohammad Mahdee Jameel, Aly El Gamal

Network Intrusion Detection Systems (IDS) aim to detect the presence of an intruder by analyzing network packets arriving at an internet connected device. Data-driven deep learning systems, popular due to their superior …

Federated LearningIntrusion DetectionNetwork Intrusion Detection

Investigating Application of Deep Neural Networks in Intrusion Detection System Design

2025-01-27 · Mofe O. Jeje

Despite decades of development, existing IDSs still face challenges in improving detection accuracy, evasion, and detection of unknown attacks. To solve these problems, many researchers have focused on designing and deve…

feature selectionIntrusion DetectionNetwork Intrusion Detection

KAIROS: Stateful, Context-Aware Power-Efficient Agentic Inference Serving

2026-04-17 · Yichao Yuan, Mosharaf Chowdhury, Nishil Talati arxiv

Power has become a central bottleneck for AI inference. This problem is becoming more urgent as agentic AI emerges as a major workload class, yet prior power-management techniques focus almost entirely on single-turn LLM…