Stochastic Dynamic Information Flow Tracking Game using Supervised Learning for Detecting Advanced Persistent Threats
Shana Moothedath, Dinuka Sahabandu, Joey Allen, Linda Bushnell, Wenke, Lee, Radha Poovendran

TL;DR
This paper models the interaction between advanced persistent threats and dynamic information flow tracking as a stochastic game, proposing novel algorithms with machine learning to improve detection accuracy and reduce false positives and negatives.
Contribution
It introduces a game-theoretic framework for APT detection using DIFT, with new algorithms including a value iteration method and a hierarchical supervised learning approach for unknown scenarios.
Findings
Algorithms validated on real attack datasets.
Proposed methods improve detection accuracy.
Convergence of the algorithms is theoretically proven.
Abstract
Advanced persistent threats (APTs) are organized prolonged cyberattacks by sophisticated attackers. Although APT activities are stealthy, they interact with the system components and these interactions lead to information flows. Dynamic Information Flow Tracking (DIFT) has been proposed as one of the effective ways to detect APTs using the information flows. However, wide range security analysis using DIFT results in a significant increase in performance overhead and high rates of false-positives and false-negatives generated by DIFT. In this paper, we model the strategic interaction between APT and DIFT as a non-cooperative stochastic game. The game unfolds on a state space constructed from an information flow graph (IFG) that is extracted from the system log. The objective of the APT in the game is to choose transitions in the IFG to find an optimal path in the IFG from an entry point…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Smart Grid Security and Resilience
