Winemaking: Extracting Essential Insights for Efficient Threat Detection in Audit Logs
Weiheng Wu, Wei Qiao, Wenhao Yan, Bo Jiang, Yuling Liu, Baoxu Liu,, Zhigang Lu, JunRong Liu

TL;DR
Winemaking is a lightweight, knowledge distillation-based threat detection system that enhances accuracy and speed in analyzing audit log provenance graphs, effectively reducing neighbor noise and utilizing prior knowledge.
Contribution
The paper introduces Winemaking, a novel graph-based threat detection framework employing knowledge distillation and graph Laplacian regularization for improved efficiency and accuracy.
Findings
Achieves higher detection accuracy than existing IDS methods.
Operates 1.4 to 5.2 times faster than state-of-the-art solutions.
Effectively reduces neighbor noise in provenance graphs.
Abstract
Advanced Persistent Threats (APTs) are continuously evolving, leveraging their stealthiness and persistence to put increasing pressure on current provenance-based Intrusion Detection Systems (IDS). This evolution exposes several critical issues: (1) The dense interaction between malicious and benign nodes within provenance graphs introduces neighbor noise, hindering effective detection; (2) The complex prediction mechanisms of existing APTs detection models lead to the insufficient utilization of prior knowledge embedded in the data; (3) The high computational cost makes detection impractical. To address these challenges, we propose Winemaking, a lightweight threat detection system built on a knowledge distillation framework, capable of node-level detection within audit log provenance graphs. Specifically, Winemaking applies graph Laplacian regularization to reduce neighbor noise,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques
