Host Attack Detection Based on XGBoost and Community Discovery
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    In a large-scale network, the security threats faced by the host are becoming increasingly diverse. With the rapid rise of technology based on machine learning to detect malicious files, the ability to detect malware has been greatly improved, and it has also forced adversaries to change their attack strategies. Among them, the “Living off the land” strategy achieves malicious behavior by calling operating system tools or automated management programs that perform tasks. Threat detection can find suspicious behavior in the context of parent and child processes. The parent-child process chain and the related events derived from it are regarded as an undirected graph, and the supervised learning XGBoost algorithm is used for weight distribution to generate an undirected weighted graph. Finally, a community discovery algorithm is employed to identify larger attack sequences from the graph. The above algorithm is verified on the simulated attack dataset of MIRTE ATT & CK.

    Reference
    Related
    Cited by
Get Citation

朱元庆,李赛飞,李洪赭.基于XGBoost和社区发现的主机攻击行为检测.计算机系统应用,2021,30(12):147-154

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:February 22,2021
  • Revised:March 28,2021
  • Adopted:
  • Online: December 10,2021
  • Published:
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063