paper-with-me

Papers

Unsupervised Threat Hunting using Continuous Bag-of-Terms-and-Time (CBoTT)

2024-03-15 · Varol Kayhan, Shivendu Shivendu, Rouzbeh Behnia, Clinton Daniel, Manish Agrawal

Threat hunting is sifting through system logs to detect malicious activities that might have bypassed existing security measures. It can be performed in several ways, one of which is based on detecting anomalies. We propose an unsupervised framework, called continuous bag-of-terms-and-time (CBoTT), and publish its application programming interface (API) to help researchers and cybersecurity analysts perform anomaly-based threat hunting among SIEM logs geared toward process auditing on endpoint devices. Analyses show that our framework consistently outperforms benchmark approaches. When logs are sorted by likelihood of being an anomaly (from most likely to least), our approach identifies anomalies at higher percentiles (between 1.82-6.46) while benchmark approaches identify the same anomalies at lower percentiles (between 3.25-80.92). This framework can be used by other researchers to conduct benchmark analyses and cybersecurity analysts to find anomalies in SIEM logs.

📄 PDF Abstract BibTeX arXiv:2403.10327

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Enabling Efficient Cyber Threat Hunting With Cyber Threat Intelligence

2020-10-26 · Peng Gao, Fei Shao, Xiaoyuan Liu, Xusheng Xiao 외

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the rich ext…

A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence

2021-01-17 · Peng Gao, Fei Shao, Xiaoyuan Liu, Xusheng Xiao 외

Log-based cyber threat hunting has emerged as an important solution to counter sophisticated cyber attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the ri…

Securing the Future: Proactive Threat Hunting for Sustainable IoT Ecosystems

2024-06-21 · Saeid Ghasemshirazi, Ghazaleh Shirvani

In the rapidly evolving landscape of the IoT, the security of connected devices has become a paramount concern. This paper explores the concept of proactive threat hunting as a pivotal strategy for enhancing the security…

Policy-Guided Threat Hunting: An LLM enabled Framework with Splunk SOC Triage

2026-03-25 · Rishikesh Sahay, Bell Eapen, Weizhi Meng, Md Rasel Al Mamun 외 arxiv

With frequently evolving Advanced Persistent Threats (APTs) in cyberspace, traditional security solutions approaches have become inadequate for threat hunting for organizations. Moreover, SOC (Security Operation Centers)…

Reinforcement Learning

Benchmarking LLM-Assisted Blue Teaming via Standardized Threat Hunting

2025-09-28 · Yuqiao Meng, Luoxi Tang, Feiyang Yu, Xi Li 외 arxiv

As cyber threats continue to grow in scale and sophistication, blue team defenders increasingly require advanced tools to proactively detect and mitigate risks. Large Language Models (LLMs) offer promising capabilities f…