Machine Learning and Feature Engineering for Detecting Living off the Land Attacks

Tiberiu Boros,Andrei Cotaie, Antrei Stan, Kumar Vikramjeet,Vivek Malik, Joseph Davidson

PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, BIG DATA AND SECURITY (IOTBDS)(2022)

引用 0|浏览1
暂无评分
摘要
Among the methods used by attackers to avoid detection, living off the land is particularly hard to detect. One of the main reasons is the thin line between what is actually operational/admin activity and what is malicious activity. Also, as shown by other research, this type of attack detection is underrepresented in Anti-Virus (AV) software, mainly because of the high risk of false positives. Our research focuses on detecting this type of attack through the use of machine learning. We greatly reduce the number of false detection by corpora design and specialized feature engineering which brings in-domain human expert knowledge. Our code is open-source and we provide pre-trained models.
更多
查看译文
关键词
Machine Learning, Living-off-the-Land (LotL), Feature Engineering, Artificial Intelligence, Random Forest, Commands, CommandLine, OpenSource, Linux
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要