Skip to Main content Skip to Navigation
Journal articles

From TTP to IoC: Advanced Persistent Graphs for Threat Hunting

Aimad Berady 1 Mathieu Jaume 2 Valérie Viet Triem Tong 1 Gilles Guette 1
1 CIDRE - Confidentialité, Intégrité, Disponibilité et Répartition
CentraleSupélec, Inria Rennes – Bretagne Atlantique , IRISA-D1 - SYSTÈMES LARGE ÉCHELLE
Abstract : Defenders fighting against Advanced Persistent Threats need to discover the propagation area of an adversary as quickly as possible. This discovery takes place through a phase of an incident response operation called Threat Hunting, where defenders track down attackers within the compromised network. In this article, we propose a formal model that dissects and abstracts elements of an attack, from both attacker and defender perspectives. This model leads to the construction of two persistent graphs on a common set of objects and components allowing for (1) an omniscient actor to compare, for both defender and attacker, the gap in knowledge and perceptions; (2) the attacker to become aware of the traces left on the targeted network; (3) the defender to improve the quality of Threat Hunting by identifying false-positives and adapting logging policy to be oriented for investigations. In this article, we challenge this model using an attack campaign mimicking APT29, a real-world threat, in a scenario designed by the MITRE Corporation. We measure the quality of the defensive architecture experimentally and then determine the most effective strategy to exploit data collected by the defender in order to extract actionable Cyber Threat Intelligence, and finally unveil the attacker.
Document type :
Journal articles
Complete list of metadata

https://hal.inria.fr/hal-03131262
Contributor : Aimad Berady Connect in order to contact the contributor
Submitted on : Thursday, February 4, 2021 - 11:16:51 AM
Last modification on : Friday, January 21, 2022 - 3:12:52 AM
Long-term archiving on: : Wednesday, May 5, 2021 - 6:23:37 PM

File

Final version TNSM - From TTP ...
Files produced by the author(s)

Identifiers

Citation

Aimad Berady, Mathieu Jaume, Valérie Viet Triem Tong, Gilles Guette. From TTP to IoC: Advanced Persistent Graphs for Threat Hunting. IEEE Transactions on Network and Service Management, IEEE, 2021, Special Issue on Latest Developments for Security Management of Networks and Services, 18 (2), pp.1321 - 1333. ⟨10.1109/TNSM.2021.3056999⟩. ⟨hal-03131262⟩

Share

Metrics

Les métriques sont temporairement indisponibles